Skip to content

harden aur_pre_build #2228

@lilydjwg

Description

@lilydjwg
Member

问题类型 / Type of issues

  • 其它 / other

受影响的软件包 / Affected packages


aur_pre_build API 支持指定 AUR 维护者已经有一段时间了,不过采用率很不好看。现在我计划将指定 AUR 维护者作为必填,以避免 AUR 包被别人接手后加入恶意或者垃圾代码。

maintainers 参数可以是 str 或者 list[str],指定信任的 AUR 维护者/最后打包者。如果 lilac 打包时,最后打包者不在这个参数里,将会拒绝打包。请各维护者更新相关包,指定该参数。


There has been some time that the aur_pre_build API supports specifying AUR maintainers. However, it's not widely used. Now I'm going to make it mandatory to specify AUR maintainers to avoid AUR packages with evil or poor code that's added by later adopter.

The maintainers argument can be str or list[str] to specify trusted AUR maintainers / last packagers. When lilac packages, if the last packager is not in this argument, lilac will refuse to package. Please add this argument for your packages!

Activity

lilacbot

lilacbot commented on May 10, 2021

@lilacbot
Contributor

NOTE: some affected packages are unmaintained:

  • freeradius-client is depended by ocserv (@farseerfc)
  • fsharp is depended by monodevelop-stable (@farseerfc)
  • libpcl is depended by ocserv (@farseerfc)

Some maintainers (perhaps outside contributors) cannot be assigned: @Rasphino, @edward-p, @OriginCode, @xgdgsc, @Xuanwo, @hamkido, @felixonmars, @kaseiwang, @rayfalling, @Universebenzene, @Skywol, @renyuneyun, @farseerfc, @isjerryxiao, @oldherl, @imlonghao, @swordfeng, @ideal, @PeterCxy, @VOID001, @yuyichao, @petronny, @h0cheung, @MarvelousBlack, @zsrkmyn, @megrxu, @berberman, @heavysink, @KenOokamiHoro, @frantic1048, @SilverRainZ, @hubutui, @masakichi, @wfxr, @ykelvis, @poscat0x04, @justforlxz, @yan12125, @yuutaw, @Sasasu

petronny

petronny commented on May 10, 2021

@petronny
Member

呃,那我不想用这个参数怎么办呢,指定None?
我目前还没有遇到需要这种白名单的包,不是觉得这个很有必要。。。

如果真要做的话,估计需要一个脚本直接批量添加现有maintainers,手动改不现实。

OriginCode

OriginCode commented on May 10, 2021

@OriginCode
Member

shadowsocks-libev-qrcode does not fetch updates from AUR, please remove it from the list.

lilydjwg

lilydjwg commented on May 10, 2021

@lilydjwg
MemberAuthor

105 remaining items

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

no-lilacMake lilac skip this issue

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

    Development

    Participants

    @ideal@lilydjwg@peeweep@cuihaoleo@hubutui

    Issue actions

      harden aur_pre_build · Issue #2228 · archlinuxcn/repo