> they can always unlink it at GitHub That is not the case, you can only remove the fork relationship on GH if there are no child forks.
And fork status has no relation to how secure the package is. Martin On Fri, Oct 9, 2026 at 12:26 PM Andreas Reichel <[email protected]> wrote: > > I am sorry for asking a provocative question: Is it wise to allow AUR > packages on forked on GitHub packages, that are forks of other packages only? > > Reason: > 1) as long as it is a fork, Github does not show it separately and associates > it with the original project -- which allows a kind of hiding from scrutiny > 2) it appears to easy, to fork a project, add malicious content and then > inject it into AUR > > If there is substance to the fork, they can always unlink it at GitHub and > (only) then it becomes full visible. > > Best and cheers > Andreas > > > On Fri, 2026-10-09 at 11:03 +0200, Robin Candau wrote: > > On 10/9/26 10:54 AM, Saren wrote: > > For more information, after a simple research, I found that > > - AUR user "CxOrg" solely uploads packages with upstream github user is > "ixnewton" > > - all of the ixnewton's github repos have commits pushed with message > "Add security audit workflow" 12 hours ago. > > On 10/9/26 16:46, Saren wrote: > > (Revised due to accidental reply to an old thread) > > Package:https://aur.archlinux.org/packages/plasma6-applet-quicklaunch > > Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/ > > Problematic Upstream File: > https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml > > The "security-audit.yml" which will be executed in actions runner is > actually extracting API keys and cloud creds and upload them to an > external server. Although I believe that building this package using > PKGBUILD harmless, the package upstream cannot be trusted anymore. > > Also note that the package submitter/maintainer may not be affiliated > with the upstream author. > > > > Hi Saren, > > Thanks for the report! > > I've blocked the "CxOrg" AUR user and I'm currently in the process of > deleting every packages that points to a repo containing this malicious > file. > > Given it's executed on the github action, the PKGBUILD itself should > probably be safe indeed, but let's take no chances. > > I will also report the repository to GitHub and contact the maintainer. > > -- > Regards, > Robin Candau / Antiz > >
