For more information, after a simple research, I found that

- AUR user "CxOrg" solely uploads packages with upstream github user is 
"ixnewton"

- all of the ixnewton's github repos have commits pushed with message 
"Add security audit workflow" 12 hours ago.

On 10/9/26 16:46, Saren wrote:
> (Revised due to accidental reply to an old thread)
>
> Package:https://aur.archlinux.org/packages/plasma6-applet-quicklaunch
>
> Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/
>
> Problematic Upstream File:
> https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml
>
> The "security-audit.yml" which will be executed in actions runner is
> actually extracting API keys and cloud creds and upload them to an
> external server. Although I believe that building this package using
> PKGBUILD harmless, the package upstream cannot be trusted anymore.
>
> Also note that the package submitter/maintainer may not be affiliated
> with the upstream author.

Reply via email to