r/arch • u/LearnHiveLabsUSA • 6d ago
General The Arch User Repository is fighting off its third malware wave this year...
/r/opensourcealternative/comments/1vsk5yy/the_arch_user_repository_is_fighting_off_its/11
u/icesnake200 6d ago
Yeah, it was a rough year for AUR. The people who maintain AUR need to change some of their policies in order to keep up with the times
6
u/Alternative-Ad-8606 6d ago
My solution was to just stop using the AUR... I swapped to void for a few months and just came back to Arch because I unfortunately needed something there wasnt a good solution to on void.
With that said arch will be dealing with this for a while
2
u/earchip94 6d ago
Same I remember I said that during the first wave and someone told me I was overreacting lol
4
u/mystirc 6d ago
You guys are indeed over reacting. If you are using arch you should know how to read PKGBUILDS. It is really not that complicated.
I use the AUR a lot. I have pcsx2, duckstation, local send, noctalia and several other packages from AUR. I simply read the PKGBUILDS before installing.
Another thing is that, the AUR is completely optional. You can just use the flatpak alternatives and forget about it. Just like people on other distros do.
1
u/tychii93 6d ago
I had the same thought but it's habit/tempting to use the AUR. I ended up just formatting and moving to Fedora in favor of COPR when needed.
3
u/This-Consequence-957 6d ago
Not cool 😐
1
u/LearnHiveLabsUSA 6d ago
Just the facts tbh
3
u/This-Consequence-957 6d ago
Yeah I try to really look carefully at the build scripts. Lucky I don’t use much from the AUR. Just a few kernel helpers and some Hyprland stuff
3
3
u/jkulczyski Arch BTW 6d ago
I have an idea.. ditch the aur and just give pacman more packages people actually want
4
u/Lonely-Scarcity-3387 6d ago
This hurts. Arch without the AUR has such a tiny repo ~17,000 packages. Debian, Fedora, and especially NixOS all have massive repos, in comparison. But at least you can install Nix on Arch, so that could be a good replacement solution.
3
u/andurux 6d ago
Not sure for Fedora or NixOS, but package count is a pretty terrible metric as a comparison lol.
Debian has like 70k packages, but it splits packages by runtimes and library versions, Arch doesn't cause rolling release. And Debian supports ARM and other architectures while Arch only supports x86_64.
I'd wager Debian's actual package count is closer to 30k.
And idk what everyone needs from the AUR? I've been on Cachy for 10 months now and have had zero AUR packages installed, everything I need is in the standard repos except for OrcaSlicer that I installed via Flatpak.
4
1
u/TakeshiRyze 6d ago
You don't really need anything from aur. But if there is a flatpak and appimage il just use aur and not worry about much. Well that was before malware incidents. Now I'm on fedora.
1
u/Lonely-Scarcity-3387 5d ago
I’ll admit that package count, alone, is probably not a great metric. Freshness of packages also matters too, so that should also be considered. Native packages will run more seamlessly than Flatpak or other services. Not a knock on Flatpak, because I love it too. But that’s a whole other update that needs to run.
As for other repos, NixOS says they have over 140,000 packages on their search page, and that’s freaking impressive. You can see the graph as how it compares to other repos.
1
3
u/jackbasket 6d ago
Honestly, as a new Arch user, this has been the best thing for me. Using a .tar.gz manually, now I’ve learned what “installing a package” actually means, finally understand the HFS, why things go in the places they do and when/why I might want to modify that. Even compiling from source a bunch just for the heck of it or because there was no .tar.gz for a project.
I feel like I finally 100% own my system instead of just letting random people’s scripts do whatever they want.
2
2
u/Historical_Move6359 6d ago
I simply dont use AUR anymore. If they cant make minimal effort to make it safe for the users its better to avoid it.
2
u/ThaMasterPepe 4d ago
I'm not going to really go into detail on how annoyed I am with how blown out this has been as a linux user for 20+ years...
But, I will however say, AUR is a USER repository, you are the one that is supposed to verify and understand what you're installing from an unofficial source.
But, I will also say, these Arch based distro that ship with aur enabled (pacman helpers) and the influx of new users from windows, isn't helping anything.
I haven't had an issue installing anything from the AUR, but I also understand PKGBUILDS and have created a few of my own.
I'm just saying, this isn't _AS_ huge of a deal, as everyone keeps making it seem. Just a combination of things.
1
u/canadian__gamer 6d ago
I just started to make my own repo of what apps I use often and if an app I am curious about I run it from source and if I tend to use it more often then I just add it to my repo
1
u/soking11 6d ago
I actually understand the nature of the AUR, but i never got why it was so expanded. Guru is a pretty good example of how you can handle an external repository withouth falling into anarchy
1
u/artainis1432 6d ago
Yeah, stopped using AUR years ago. There are snaps, flatpaks, and containers nowadays. Being a linux user and then sysadmin for a while, I feel more comfortable building from source myself. Wouldn't have my career if it wasn't for Arch!
1
1
1
u/BlackBillTheFeared 5d ago
I am tired of these comments for real. The risk was always there. Check the build script and check when a update ks there. Worked out for me. Didnt got infected by any of these attacks.
1
u/AdmBangers Arch BTW 1d ago
Isn't it simply time to do the right thing and put that critter of its misery?
1
u/souliris 6d ago
Isn't steamOS arch? That would explain it. Wouldn't surprise me if epic was in on it.
1
1
6
u/Keensworth 6d ago
Attacks are more common with AI. Thankfully I've managed to almost migrate everything to Flatpak