I am sorry for asking a provocative question: Is it wise to allow AUR packages on forked on GitHub packages, that are forks of other packages only?
Reason: 1) as long as it is a fork, Github does not show it separately and associates it with the original project -- which allows a kind of hiding from scrutiny 2) it appears to easy, to fork a project, add malicious content and then inject it into AUR If there is substance to the fork, they can always unlink it at GitHub and (only) then it becomes full visible. Best and cheers Andreas On Fri, 2026-10-09 at 11:03 +0200, Robin Candau wrote: > On 10/9/26 10:54 AM, Saren wrote: > > For more information, after a simple research, I found that > > > > - AUR user "CxOrg" solely uploads packages with upstream github > > user is > > "ixnewton" > > > > - all of the ixnewton's github repos have commits pushed with > > message > > "Add security audit workflow" 12 hours ago. > > > > On 10/9/26 16:46, Saren wrote: > > > (Revised due to accidental reply to an old thread) > > > > > > Package: > > > https://aur.archlinux.org/packages/plasma6-applet-quicklaunch > > > > > > Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/ > > > > > > Problematic Upstream File: > > > https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml > > > > > > The "security-audit.yml" which will be executed in actions runner > > > is > > > actually extracting API keys and cloud creds and upload them to > > > an > > > external server. Although I believe that building this package > > > using > > > PKGBUILD harmless, the package upstream cannot be trusted > > > anymore. > > > > > > Also note that the package submitter/maintainer may not be > > > affiliated > > > with the upstream author. > > > > Hi Saren, > > Thanks for the report! > > I've blocked the "CxOrg" AUR user and I'm currently in the process of > deleting every packages that points to a repo containing this > malicious > file. > > Given it's executed on the github action, the PKGBUILD itself should > probably be safe indeed, but let's take no chances. > > I will also report the repository to GitHub and contact the > maintainer. > > -- > Regards, > Robin Candau / Antiz
