On 8/3/26 2:18 PM, [email protected] wrote:
But the malicious actor is still the maintainer. Shouldn't packages be
taken away from malicious maintainers?


The malicious maintainer's account is banned and cannot push changes to the package anymore. Orphaning should be coordinated. If we orphan the package without someone willing to adopt it after it, it's a risk that it gets re-adopted by a malicious bot account right away (right now adoptions are disabled anyway but you get the point).

Given the current circumstances, it's actually safer to have the banned account locking the package rather then just making it orphan and taking the risk for it to be re-adopted right away by another malicious account.
If you're interested in taking the maintenance, let us know though.

On Sun, 02 Aug 2026 08:10:30 +0000, [email protected] wrote
about "[PRQ#85271] Orphan Request for meshcore-open-git Rejected":

Request #85271 has been Rejected by yan12125 [1]:

Thanks for the information. The malicious commit is dropped by Antiz.

[1] https://aur.archlinux.org/account/yan12125/


--
Regards,
Robin Candau / Antiz

Attachment: OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to