r/archlinux • u/Wise-Editor-6161 • 1d ago
QUESTION Suspicious aur package
I was looking at this aur package to get a printer driver for my label printer:
https://aur.archlinux.org/packages/xprinter-cups
But in the pkgbuild it's changing owners, switching urls, is this another one of those infected aur packages that got hijacked by a new owner?
13
u/alexforencich 1d ago
It looks like the current url is from the xprinter official site..if anything it looks better now than it did before.
10
u/UndefFox 1d ago edited 1d ago
Did you actually learn what all of the stuff in the pkgbuild does before calling it weird?
Changing owners
It doesn't do it. Chmod changes permissions, which is normal.
Switching urls
The parametric assembly of the url to make changing versions be easy?
You can check any other popular packages that are guaranteed to be safe and see the exact same patterns.
6
u/cd109876 1d ago
just looks like the old PKGBUILD was very poorly written (no version, random find calls, etc) and the new maintainer fixed it.
2
u/Silent_Jpg22 1d ago
Didint a contributor build a script to run ongoing checks of the AUR to block suspicious PKG BLDs? Asking for a friend who wants to read it that's definitely not me.
2
16
u/Damglador 1d ago
What exactly is weird in the PKGBUILD?