Thanks to the previous uploader collaboration (Amiad), I've gotten control of 
the trustsight package in the AUR.

I've just released trustsight v0.16.1, with multiple fixes, a detached 
tokenizer and I've uploaded it to the AUR. Package main download source is 
still officially the github repository, not AUR, but I'll keep maintaining it 
as to keep ownership (as to comply as much as possible with the security model).

Thanks to Olav for reporting multiple vulnerabilities and issues.

One note. Olav said:
> But it could be a proposal to include it in AUR helpers.

Is there a specific path to apply there? Or is it fully up to the TUs? That 
would be the end goal imo. Trustsight was designed specifically with the 
detailed security layer model I mentioned above, and I see the AUR moving 
towards there on its own, even before this thread. I see trustsight as a piece 
of the puzzle.

This tool is far from finished, and its main block right now is adoption: few 
users = few reports, so slower evolution. I will keep working in this tool, and 
its harness, which allows me (and whoever wants really) to find more bypasses 
to patch. Trustsight fully detects the Atomic Arch campaign, and the --depth / 
--deps flag give another layer of protection against future supply chain 
attacks.

Att.

Emiliano


> Emiliano Gandini Outeda
> emiliano-go [dot] com
> emiliano.gandini@protonmail [dot] com

Attachment: publickey - [email protected] - 0xF759D6D4.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to