Hello,

Em qua., 23 de set. de 2026, 22:57, Alexander Berg <[email protected]>
escreveu:

> Maarten is right on both counts, and I take them.
>
> The defect detail belonged in the project's issue tracker, not on this
> list.
> The maintainer has the full material, and anything further I find goes
> there.
>
> The wording was the bigger mistake. I wrote in the tool's own internal
> terms
> without explaining a single one. If a paragraph only parses for the author
> of
> the code, it has no business on a list of several hundred people - that is
> on
> me, not on the reader.
>
> One point from the original thread does belong here, in plain words. The
> advice
> we give users is "read the PKGBUILD", but what runs as root also includes
> the
> install scriptlet and any patch files committed next to the recipe. A tool
> that
> reads only the recipe matches the advice and misses the attack. Whatever
> the
> AUR ends up blessing, that is the gap worth closing.
>
> Alexander Berg
>

I would also bet on reproducible builds for this security issue; I’ve
already seen some initial work on that.

>

Reply via email to