Re: Package maintainer for vinegar-git & vinegar is malicious.

2024-02-17 Thread sewn

On 2024-02-17 12:00, Muflone wrote:

While these types of calls about people are not welcome and contrary to 
the Code of Conduct [1], the used words were already removed in 
December.


I had to ask them several times to remove it.

This one was already removed today from the package, along with the 
package description to be more respectfully.


This was only after the orphan request, seeing as they got caught. Git 
history does not lie.




have then maliciously modified the description and changed the code of 
Vinegar to

remove a feature which was announced in our communication channels.


Could you please give more context about the part that was removed? I 
mean I see the patch which disables the lines but what is meant to 
disable?


Vinegar 1.7.0 and up has introduced a feature to allow for multiple data 
directories, which solves various different problems we used to have.
The patched code does not remove the deprecated data directory, instead 
disrespecting our upstream choice without contacting us for any other
affirmations regarding deleting it. It will take useless space 
otherwise.


Additionally, the AUR package maintainer could have added a 
'post-install' message asking the user to backup their old deprecated 
data directory,

to which they have not.


The package orphaning and account suspension will be evaluated.


I greatly appreciate your time. Thank you.


Re: Package maintainer for vinegar-git & vinegar is malicious.

2024-02-17 Thread Muflone

Hi sewn

The AUR package maintainer for my software has defaced me [1], my 
software, and
patched Vinegar maliciously [2]. I have not appreciated the direct 
insults at me.



While these types of calls about people are not welcome and contrary to 
the Code of Conduct [1], the used words were already removed in December.




They have also added a .install hook file to direct installers of the 
package to

another piece of software, which is biased and uncalled for.


This one was already removed today from the package, along with the 
package description to be more respectfully.



have then maliciously modified the description and changed the code of 
Vinegar to

remove a feature which was announced in our communication channels.



Could you please give more context about the part that was removed? I 
mean I see the patch which disables the lines but what is meant to disable?



I would like to request an urgent removal of the package maintainer 
DodoGTA from
maintaining the AUR packages for my software, they cannot be trusted and 
are malicious.


The package orphaning and account suspension will be evaluated.

regards

[1] https://terms.archlinux.org/docs/code-of-conduct/

--
Fabio Castelli aka Muflone


OpenPGP_0x930B82BFC2BDA011.asc
Description: OpenPGP public key


OpenPGP_signature.asc
Description: OpenPGP digital signature