For more information, after a simple research, I found that - AUR user "CxOrg" solely uploads packages with upstream github user is "ixnewton"
- all of the ixnewton's github repos have commits pushed with message "Add security audit workflow" 12 hours ago. On 10/9/26 16:46, Saren wrote: > (Revised due to accidental reply to an old thread) > > Package:https://aur.archlinux.org/packages/plasma6-applet-quicklaunch > > Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/ > > Problematic Upstream File: > https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml > > The "security-audit.yml" which will be executed in actions runner is > actually extracting API keys and cloud creds and upload them to an > external server. Although I believe that building this package using > PKGBUILD harmless, the package upstream cannot be trusted anymore. > > Also note that the package submitter/maintainer may not be affiliated > with the upstream author.
