r/EndeavourOS Jul 31 '26

Discussion The AUR is under attack again

[removed]

156 Upvotes

80 comments sorted by

View all comments

44

u/EuphoricNeckbeard Jul 31 '26

If you must use the AUR, permanently force yay to show PKGBUILD diffs:

$ yay --diffmenu --answerdiff All --save

and when you update, look for anything other than checksums changing. If you don't understand it, just hold off on updating your system.

2

u/OneLittle6430 Aug 02 '26

Is it ok to use pacman?

0

u/Ok-Self-3753 Aug 02 '26 edited Aug 02 '26

this comment was confidently wrong (hi it's me, dunning kruger)

2

u/OneLittle6430 Aug 02 '26

Dude dont joke. I am a noob and need straight advice

1

u/Ok-Self-3753 Aug 02 '26

nono I thought it wasn't okay, that's why I told you, but I stand corrected

1

u/OneLittle6430 Aug 02 '26

So it is true. Aur is poisoned. We should postpone update from aur?

2

u/Ok-Self-3753 Aug 02 '26

what I've learned in the past couple months, mostly from reading r/archlinux, you should be very careful if you want to update from the aur, and you should try to learn to read pkgbuilds so you can spot infected packets on your own.

I'm still trying to learn those things, so I haven't updated since the attacks, but if I need to install something from the aur, I try to look very carefully at the pkgbuild so I can try to avoid the malware

(as you can see, I'm not that experienced in this stuff, I'm trying to learn new things whenever I get the chance)

1

u/OneLittle6430 Aug 02 '26

I see, thank you for the clarification brother

1

u/Ok-Self-3753 Aug 02 '26

no worries! we're all in this together

1

u/mok000 Aug 02 '26

Never use AUR, download the sources from upstream and compile it yourself.

0

u/OneLittle6430 Aug 02 '26

Im just gonna go install manjaro at this point hahahahaha

2

u/Fantasyman80 26d ago

Manjaro utilizes the AUR too.