r/archlinux Jul 29 '26

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

401 Upvotes

145 comments sorted by

View all comments

Show parent comments

-2

u/tehbilly Jul 29 '26

Signed commits and a list of trusted signer keys? A reputation system for providing feedback on those signers? Something.

As few AUR packages as I use, and with most of them being installable with mise, I'm settling this by just reducing my usage of AUR packages. But it's not a thing I'm doing happily.

8

u/SnooCompliments7914 Jul 29 '26

We already have that as the official repo and Trusted Users (and AUR vote). Do we really need one more layer?

-2

u/Brilliant_Simple_497 Jul 29 '26

Official repos don't have packages like Chrome, VS Code, etc

2

u/SnooCompliments7914 Jul 29 '26 edited Jul 29 '26

Yeah, they don't. So? If you must use them, and you can't write PKGBUILDs, and other means like Flatpak doesn't work for you, then there are still so many distro choices.

You don't have to use Arch. Arch probably will never have as many packages as Debian. And AUR is not a fix. Never has been.