Post B7U0maZEOBvTYeLi40 by lexihexi@mastodon.social
 (DIR) More posts by lexihexi@mastodon.social
 (DIR) Post #B7TrAcDNpgOr7DW1Jo by itsfoss@mastodon.social
       0 likes, 0 repeats
       
       A new yay release with some new tools to catch suspicious packages. ⚙️👇https://itsfoss.com/news/yay-v13-release/#linux #archlinux #yay
       
 (DIR) Post #B7U0maZEOBvTYeLi40 by lexihexi@mastodon.social
       0 likes, 0 repeats
       
       @itsfoss @itsfoss damn. Just yesterday, I was pondering how am enduser could protect themselves from from formerly good but suddenly malicious packages. And I think that "showing how long it's been since a package's PKGBUILD last changed" is not enough. We need a check if there has been any sort of long pause in the maintenance activity of a package. Otherwise, an attacker could just make a benign change, then push the attack update right after so that the check script simply skips over.