19 comments

[ 4.0 ms ] story [ 37.8 ms ] thread
How did it go from "He even performed a backup/mirror of several dozen of our repositories." to "He deleted part of our repository from GitHub. (..) [He published] an empty package in the cooker repository, which obsoleted all gnome and cosmic packages."?

I feel like there's a few steps missing there. How does it go from "a new person joins the community" to "he's able to nuke everything"? Sure, he might be reasonably well-known, but in the post it doesn't sound like he was a core maintainer, or even a very active community member. Do they just randomly hand out admin access to anyone?

TIL Mandriva/Mandrake Linux is still around.
For the record there are at least 2 distros that carry the Mandriva/Mandrake legacy. Besides OpenMandriva there is also Mageia which I believe is the more popular option.
I feel like this is kinda sorta to be expected.

Every time someone actively approaches you with an offer to spend their real energy and lifetime on your thing, It's almost always about leverage in some way.

At least if there is actual work attached to it.

Money alone might be paid by people that just have too much of it or want to feel better about something.

But if they actively involve themselves to a degree that goes way beyond scratching their own itch, something's up.

You might get lucky and find a just genuinely good person, but you might also not.

You must be young, it's been decades without having a major issue.
Nearly a month ago AUR malware happen, now this - it starts to feel like there's some organized attempt to paint Linux distros as dangerous.
stop trying to make AUR sound like a place that can be compromised.

it's literary a tetanus ridden landfill, by design!

it's nothing more than a place to share one-file (one file!) recipe on how to conveniently build a repo from outside the arch tree. yes, is usually how software end up in arch (after much more work)

the fact that idiots (in the original sense of the word in Greek) made automatic installers that fools novices to think those are vetted distro packages doesn't make it so.

(comment deleted)
AUR has always been a risk and that wasn't the first attack of that kind. And here... Well, if it was coordinated, they would've picked a distro that doesn't prompt responses like: "Oh, mandriva still exists?"

Nah. Microsoft has better means to sell Windows.

>feel like there's some organized attempt to paint Linux distros as dangerous.

imo the only ones doing that are the ones that try to portray the AUR as more than it actually is. A pastebin for package builds with "run at your own risk" all over it. It would be more concerning if there wasn't anything malicious found ever other day.

"should have" "could have". Geez. This was malicious. Take legal action already!
To what end? Not every dispute needs to go to court. In this case the guy was already kicked out of the project and now publicly shamed.
I had no idea mandriva/openmandriva still existed. I still have a mandrake cd somewhere, mostly because I cannot seem to be able to depart from physical media :)
I feel for the maintaners. There is a push and pull here on OSS.

However, I have made the choice to remove all my repos from the internet and self host in the face of LLM spam.

Because Im not dependent on PRs from randos this doesnt really matter to me. I think at some point OSS repos are going to have to come to grips with the reality of hosting on github or any public git host.

And go underground. Or decide whether the juice is any longer worth the squeeze. In my mind its not unless its off the internet. You may skate today, tomorrow you are completely screwed.

Slop PRs are just spam, we learned to deal with spam on email, we'll learn to deal with this as well.

Fwiw, I don't think it's an "AI" problem, is a knowledge and respect problem from the people that have their agents dump code on FOSS projects.

interesting that i already had blocked github.com/davidebeatrici

unfortunately i did not add a note at the time

In the Stagex Linux distribution it is not possible for any single person to release anything. We require multiple independent review and reproduction signatures from the maintainer team.

We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.

I can not evaluate the claims made, but even if I am lenient and assume it is all true, to me it is still strange how a distribution becomes so dependent on a single person or provider. I can't help but wonder how other distributions would have handled that; Gentoo would probably not have ended in a similar situation, debian probably neither.

And mind you - that's only if I evaluate the claims made at face value. I also can't help but feel that there are some missing steps here. Sure, IRC roid-raging happened in the past, see #freenode, and people are strange in general, but even then it really reads oddly to me, almost as if "I trusted that scammer from Nigeria with my money because the emails were so convincing".