• sudo@programming.dev
    link
    fedilink
    arrow-up
    2
    ·
    14 hours ago

    That wouldn’t have fixed the AUR incident because the attacker updated the PKGBUILD which is roughly the same as the nixfile. And there are no packages provided by the AUR, just PKGBUILDs. You always build the package yourself locally.