• sonofearth@lemmy.worlddeleted by creator
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    3 months ago

    Maybe maintenance of packages shouldn’t just be handed over to newly created accounts. This is a design flaw on AUR’s part. As Linux popularity rises, these types of attacks will just keep growing. There should also be some sort of system where it is easy to verify that the maintainer of the package is also the actual developer. Like brave-bin has brave has the maintainer who are also the creator. Just give a green check mark to them or something.