Re: Package maintainer for vinegar-git & vinegar is malicious.

2024-02-17 Thread sewn

On 2024-02-17 12:00, Muflone wrote:

While these types of calls about people are not welcome and contrary to 
the Code of Conduct [1], the used words were already removed in 
December.


I had to ask them several times to remove it.

This one was already removed today from the package, along with the 
package description to be more respectfully.


This was only after the orphan request, seeing as they got caught. Git 
history does not lie.




have then maliciously modified the description and changed the code of 
Vinegar to

remove a feature which was announced in our communication channels.


Could you please give more context about the part that was removed? I 
mean I see the patch which disables the lines but what is meant to 
disable?


Vinegar 1.7.0 and up has introduced a feature to allow for multiple data 
directories, which solves various different problems we used to have.
The patched code does not remove the deprecated data directory, instead 
disrespecting our upstream choice without contacting us for any other
affirmations regarding deleting it. It will take useless space 
otherwise.


Additionally, the AUR package maintainer could have added a 
'post-install' message asking the user to backup their old deprecated 
data directory,

to which they have not.


The package orphaning and account suspension will be evaluated.


I greatly appreciate your time. Thank you.


Package maintainer for vinegar-git & vinegar is malicious.

2024-02-17 Thread sewn

Hi.

I am the primary developer of Vinegar (s...@disroot.org, see commits and 
members

of GitHub organization vinegarhq with repository vinegar).

The AUR package maintainer for my software has defaced me [1], my 
software, and
patched Vinegar maliciously [2]. I have not appreciated the direct 
insults at me.
They have also added a .install hook file to direct installers of the 
package to

another piece of software, which is biased and uncalled for.

Additionally, i have asked the maintainer various times to remove the 
insult directed
at me, and to update the package - to which they have not responded for 
days. They
have then maliciously modified the description and changed the code of 
Vinegar to

remove a feature which was announced in our communication channels.

I would like to request an urgent removal of the package maintainer 
DodoGTA from
maintaining the AUR packages for my software, they cannot be trusted and 
are malicious.


[1]: 
https://aur.archlinux.org/cgit/aur.git/commit/?h=vinegar=2abcbe54f64c7483d13a48679e11b772a548d97b
[2]: 
https://aur.archlinux.org/cgit/aur.git/commit/?h=vinegar=aa3b4dcad2a67e435836f060227fda90453ba774