現有會員可[按此]登入。未成為會員可[按此]註冊。
[公司模式 - 關]  [懷舊模式 - 開
[Youtube 預覽 - 關]  [大字型]  [小字型]

您現在聚腳在 軟件台內。

跳至第

發起人
Linux 高登集中討論(#15)
303 個回應
The Arch Linux User Repository "AUR" was hit by a large-scale malware campaign this week with more than 400 of these user-supplied packages being compromised. #kill#

https://www.phoronix.com/news/Arch-Linux-AUR-400-Compromised


The Arch Linux User Repository "AUR" was hit by a large-scale malware campaign this week with more than 400 of these user-supplied packages being compromised. #kill#

https://www.phoronix.com/news/Arch-Linux-AUR-400-Compromised

check過未有事住 不過下次AUR update都係認真audit下先....


https://www.youtube.com/watch?v=8KQFgWhido
Linus team人終於做到一半人dual boot
雖然Linus都未轉 因為話要做review好多windows only

食盡兩家茶禮

https://www.youtube.com/watch?v=8KQFgWhido
死左link?


原來係比高登食左某D字 玩死
8KQFgWhido


原來係比高登食左某D字 玩死
8KQFgWhido

開左粗口filter就入唔到link 笑左


The Arch Linux User Repository "AUR" was hit by a large-scale malware campaign this week with more than 400 of these user-supplied packages being compromised. #kill#

https://www.phoronix.com/news/Arch-Linux-AUR-400-Compromised

check過未有事住 不過下次AUR update都係認真audit下先....


有人寫咗個script 可以check
https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992

neovim-nvim-treesitter
rhythmbox-git
apple-music-desktop
bitcoin-core-git

仲有好多python dependencies....
極危險[shocking]


aur係邊個都可以放package上去?
同埋啲package有冇經過audit先可以上架?


原來係比高登食左某D字 玩死
8KQFgWhido

開左粗口filter就入唔到link 笑左

s/hi/hi/ [sosad]


aur係邊個都可以放package上去?
同埋啲package有冇經過audit先可以上架?

1. 任何人 不過會有個owner控制 先到先得
2. 冇 不過通常其他user會發現

所以不嬲aur都應該自己audit 不過現實係個個都懶 靠其他user通知算 O:-)
呢次出事係因為aur既機制係如果個package orphan左 即係冇人maintain 就可以拿到控制
某程度上證實左2026係year of linux 開始多hacker留言到linux易hack O:-)


The day started out with Arch Linux's AUR user-contributed repository seeing more than 400 packages compromised with malware. Now in ending out the day they believe all affected commits have been addressed. But it ended up being more than 1,500 affected packages. #kill2#
https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500


搵到個rsshub幾正
啲大陸人幾勁#adore#


所以不嬲aur都應該自己audit

Slackware 自己唔做就根本無人幫我 update
要靠slackbuilds嗰批額外嘢仲要自己拎源碼build

[slick] [bomb] [banghead]


The day started out with Arch Linux's AUR user-contributed repository seeing more than 400 packages compromised with malware. Now in ending out the day they believe all affected commits have been addressed. But it ended up being more than 1,500 affected packages. #kill2#
https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500

Just a day after Arch Linux developers believed they got their malware AUR incident under control with 1,500+ packages affected by malware, another round of of AUR malware is now being discovered. This latest round is more sophisticated as with code obfuscation to better conceal the intent.
https://www.phoronix.com/news/Arch-Linux-AUR-More-Malware

https://www.phoronix.net/image.php?id=2026&image=aur_mal_obfuscate
[fuck] [fuck] [fuck] [fuck] [fuck]


https://www.youtube.com/watch?v=oLK-OWdEm7I
如果中咗招都幾係野
Can wayland and rust fix it?


所以不嬲aur都應該自己audit

Slackware 自己唔做就根本無人幫我 update
要靠slackbuilds嗰批額外嘢仲要自己拎源碼build

[slick] [bomb] [banghead]

slackbuild 即係類似AUR?
點解仲要自己拎源碼[???]


所以不嬲aur都應該自己audit

Slackware 自己唔做就根本無人幫我 update
要靠slackbuilds嗰批額外嘢仲要自己拎源碼build

[slick] [bomb] [banghead]

slackbuild 即係類似AUR?
點解仲要自己拎源碼[???]

因為slackbuilds嘅原創內容就只有一條 build script 同埋畀pkgtook睇嘅額外嘢
條script做嘅就係拎最源頭嘅source tarball compile 一個 slackware package 畀你自己裝
大型嘅軟件好似LibreOffice就有兩套script, 一套拎官方binary重新包裝,一套係拎源碼從頭compile

呢種做法正是Slackware本色: 如非必要唔會落自己patch


所以不嬲aur都應該自己audit

Slackware 自己唔做就根本無人幫我 update
要靠slackbuilds嗰批額外嘢仲要自己拎源碼build

[slick] [bomb] [banghead]

slackbuild 即係類似AUR?
點解仲要自己拎源碼[???]

因為slackbuilds嘅原創內容就只有一條 build script 同埋畀pkgtook睇嘅額外嘢
條script做嘅就係拎最源頭嘅source tarball compile 一個 slackware package 畀你自己裝
大型嘅軟件好似LibreOffice就有兩套script, 一套拎官方binary重新包裝,一套係拎源碼從頭compile

呢種做法正是Slackware本色: 如非必要唔會落自己patch

sbotools係咪即係slackware界嘅yay[sosad]


所以不嬲aur都應該自己audit

Slackware 自己唔做就根本無人幫我 update
要靠slackbuilds嗰批額外嘢仲要自己拎源碼build

[slick] [bomb] [banghead]

slackbuild 即係類似AUR?
點解仲要自己拎源碼[???]

因為slackbuilds嘅原創內容就只有一條 build script 同埋畀pkgtook睇嘅額外嘢
條script做嘅就係拎最源頭嘅source tarball compile 一個 slackware package 畀你自己裝
大型嘅軟件好似LibreOffice就有兩套script, 一套拎官方binary重新包裝,一套係拎源碼從頭compile

呢種做法正是Slackware本色: 如非必要唔會落自己patch

sbotools係咪即係slackware界嘅yay[sosad]

又幾似
不過sbotools作者自己話佢係移植*BSD個ports概念過去

利申:兩樣都無用過
Dependency 係睇住slackbuilds.org自己解決


有冇人有玩usb lINUX,有邊隻夠細SIZE


有冇人有玩usb lINUX,有邊隻夠細SIZE

想用黎做乜?

要細到極端比如可以到128MB 比如PuppyLinux
但正正常常一個linux desktop都係大約4GB - 6GB 唔會有USB裝唔到
比如Linux Mint, Fedora KDE


The AUR Malware Attack Never Stopped
https://www.youtube.com/watch?v=VeudOzqpHHs


剛剛更新系統失敗
error message話librewolf而家變咗insecure package, 要我加入條allow list先俾我裝
嚇死我,即刻查咩事
然後搵到呢個PR
https://github.com/NixOS/nixpkgs/pull/531706
原來係有個librewolf contributor PR要求update最新version, 但過咗兩個月都冇人review同merge, 然後佢發老脾mark librewolf做insecure package
security team leader Martin Weinelt一句comment都冇留低直接approve 呢個PR就算
真係頂唔順 成件事都幾白痴


剛剛更新系統失敗
error message話librewolf而家變咗insecure package, 要我加入條allow list先俾我裝
嚇死我,即刻查咩事
然後搵到呢個PR
https://github.com/NixOS/nixpkgs/pull/531706
原來係有個librewolf contributor PR要求update最新version, 但過咗兩個月都冇人review同merge, 然後佢發老脾mark librewolf做insecure package
security team leader Martin Weinelt一句comment都冇留低直接approve 呢個PR就算
真係頂唔順 成件事都幾白痴

諗緊arch linux某程度上都幾痴線 好似話60% package都係一個人maintain
nixos仲要support更多package入repo 唔夠人手正常 用埋呢D niche browser就唯有自己maintain


依家先發現原來android ssh app "ConnectBot"支援用指模解鎖ssh private key登入server
有冇人有用?


剛剛更新系統失敗
error message話librewolf而家變咗insecure package, 要我加入條allow list先俾我裝
嚇死我,即刻查咩事
然後搵到呢個PR
https://github.com/NixOS/nixpkgs/pull/531706
原來係有個librewolf contributor PR要求update最新version, 但過咗兩個月都冇人review同merge, 然後佢發老脾mark librewolf做insecure package
security team leader Martin Weinelt一句comment都冇留低直接approve 呢個PR就算
真係頂唔順 成件事都幾白痴

諗緊arch linux某程度上都幾痴線 好似話60% package都係一個人maintain
nixos仲要support更多package入repo 唔夠人手正常 用埋呢D niche browser就唯有自己maintain

我估係因為librewolf用得多build server資源,又update得密,所以借啲依唔merge, 因為一merge就trigger rebuild
nixos差唔多兩年唔接受新package request, 好似都搞唔掂
arch linux嗰個maintainer係咪叫felix yan[sosad]


跳至第



  快速回覆 - 輸入以下項目

本討論區現只接受會員張貼文章,本站會員請先登入。非會員人仕,您可以按此加入為新會員,費用全免,並可享用其他會員服務。


上次光臨時間: 19/6/2026 22:32
今天貼文總數: 553 | 累積文章數目: 7,501,502

聯絡我們 |  服務條款 |  私隱政策
Copyright © 2026 HKGolden.com. All Rights Reserved.