Thanks to the previous uploader collaboration (Amiad), I've gotten control of the trustsight package in the AUR.
I've just released trustsight v0.16.1, with multiple fixes, a detached tokenizer and I've uploaded it to the AUR. Package main download source is still officially the github repository, not AUR, but I'll keep maintaining it as to keep ownership (as to comply as much as possible with the security model). Thanks to Olav for reporting multiple vulnerabilities and issues. One note. Olav said: > But it could be a proposal to include it in AUR helpers. Is there a specific path to apply there? Or is it fully up to the TUs? That would be the end goal imo. Trustsight was designed specifically with the detailed security layer model I mentioned above, and I see the AUR moving towards there on its own, even before this thread. I see trustsight as a piece of the puzzle. This tool is far from finished, and its main block right now is adoption: few users = few reports, so slower evolution. I will keep working in this tool, and its harness, which allows me (and whoever wants really) to find more bypasses to patch. Trustsight fully detects the Atomic Arch campaign, and the --depth / --deps flag give another layer of protection against future supply chain attacks. Att. Emiliano > Emiliano Gandini Outeda > emiliano-go [dot] com > emiliano.gandini@protonmail [dot] com
publickey - [email protected] - 0xF759D6D4.asc
Description: application/pgp-keys
signature.asc
Description: OpenPGP digital signature
