Hello, Em qua., 23 de set. de 2026, 22:57, Alexander Berg <[email protected]> escreveu:
> Maarten is right on both counts, and I take them. > > The defect detail belonged in the project's issue tracker, not on this > list. > The maintainer has the full material, and anything further I find goes > there. > > The wording was the bigger mistake. I wrote in the tool's own internal > terms > without explaining a single one. If a paragraph only parses for the author > of > the code, it has no business on a list of several hundred people - that is > on > me, not on the reader. > > One point from the original thread does belong here, in plain words. The > advice > we give users is "read the PKGBUILD", but what runs as root also includes > the > install scriptlet and any patch files committed next to the recipe. A tool > that > reads only the recipe matches the advice and misses the attack. Whatever > the > AUR ends up blessing, that is the gap worth closing. > > Alexander Berg > I would also bet on reproducible builds for this security issue; I’ve already seen some initial work on that. >
