Be real for a second,
Did you, or did you not, manage to review a diff, and say “no, that looks fishy”.
Do you really think you are immune from compromised binary AUR packages thats being downloaded straight from GitHub? Sure, now it’s not only the AUR that’s bad, but in the end of the day, a malicious binary did arrive at your computer.
Let’s say that you don’t use *-bin packages, and only download from compilable source, are you immune from the strategy that the state actor who caused CVE-2024-3094 used to compromise packages?







My theory is that is the result of complaints from customers after they get a visit from AI crawlers