Package: https://aur.archlinux.org/packages/plasma6-applet-quicklaunch

Upstream: https://github.com/ixnewton/org.kde.plasma.quicklaunch/

Problematic Upstream File: 
https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml

The "security-audit.yml" which will be executed in actions runner is 
actually extracting API keys and cloud creds and upload them to an 
external server. Although I believe that building this package using 
PKGBUILD harmless, the package upstream cannot be trusted anymore.

Also note that the package submitter/maintainer may not be affiliated 
with the upstream author.


Reply via email to