A quick note on process regarding the recent AUR story. Everything worked exactly as community-driven threat intel should.
1. A user tipped us off
2. We investigated and reported
3. Community information refined the information
4. Everyone got the necessary information
We protected each other.
Or uhhh 3 minutes! Wow Fedora Server upgrades are quick.
The wave appears to have subsided for now. The response of the AUR maintainers was praiseworthy indeed, although without some process/policy changes, this could happen again at any time.
The wave appears to have subsided for now. The response of the AUR maintainers was praiseworthy indeed, although without some process/policy changes, this could happen again at any time.