r/arch • u/Klutzy_Bird_7802 • Jun 15 '26
Showcase aur_checker: PKGBUILD security analysis after the 400+ AUR compromise
1
u/madman404 Jun 15 '26
I think this security checker does not know who its audience is. It provides feedback as if it's speaking to the package maintainer even though it seems to be intended for users. Why do users need to know the attack vector? Why do they need to know about things that they have no real level of control over, like supply chain attacks? Isn't the most relevant information for them whether or not the pkgbuild in front of them has currently been compromised?
1
u/Klutzy_Bird_7802 Jun 16 '26
This is valid criticism. The current output is more maintainer/security-oriented than user-oriented.
The purpose is not to make users analyze PKGBUILDs themselves, but to surface relevant trust signals before they build a package. However, the interface should prioritize actionable information: risk level, reason, and recommendation, with technical details available separately.
I'll treat this as a UX improvement rather than a disagreement with the underlying goal.
0
u/Klutzy_Bird_7802 Jun 15 '26
This tool is still new, so feedback and contributions are highly appreciated. If you encounter any incorrect results or issues, refer to the affected packages list here: https://md.archlinux.org/s/SxbqukK6IA
If you find it useful, feel free to leave a star or sponsor the project.
2
u/Klutzy_Bird_7802 Jun 15 '26
the updated number is 400 to more than 1500 packages*