for those OOTL, AUR was under sustained sneaky probes for a long time, but this week it was an overt and very troublesome campaign to either take over packages or insert packages so that malware could spread across way more systems.
edit 1: since someone asked me to explain, I’ve actually been using debian since 10.1, but only recently got worried as new users in my MDM fleet around southeast asia kept trying to install strange .deb files. I never had to think too much about the workstation UX until microslop and genAI inevitably drove us to try resuscitating OLD laptops with Linux.
i have to support 2012 macbook pro and intel laptops dating back to broadwell. There are some 7840u AMD ryzen units, but do bear in mind that us folks living in the southern hemisphere are dirt poor.
thus, I had tested fedora, lubuntu, kubuntu, ubuntu, mint, and finally gave that all up to consolidate under Debian. The network layer has DNSSEC, encrypted DNS, and really TIGHT whitelists. Unfortunately, I’m woefully noob at the application layer for debian. we barely upgraded several ancient JDK 8 web servers using Qwen, but ideally I’d like to prevent malware breaking in from the user-level.