4 ms·
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories
- 2bluesc 3y agoShould note this only applies to AUR packages and `-git` mostly because of missing archive hashes. AUR packages pinned to mutable tags are easiest to hijack.
- _emacsomancer_ 3y agoarticle notes that they "found nine vulnerable packages (in the community repository)"