ChimeraOS / ChimeraOS/chimeraos
aur-orphan-compromise
Open
- Dominant language
- Shell
- Stars
- 2k
- Forks
- 131
- PR merge metrics
- No merged PRs in 30d
Description
Hey,
there is an ongoing attack running inside the AUR. To me it seems like ChimeraOS is not affected by this, unless the user explicitly installs a compromised package manually. Still I wanted to double check here if this is the case?
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by checking how ChimeraOS obtains packages and whether its normal operation exposes users to compromised AUR packages. Compare that path with the attack described in the issue, then document whether ChimeraOS is affected without manually installing an AUR package and record the supporting evidence.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- arch-linux, linux
- Domain
- operating-systems, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100