@djugei, you're now the maintainer :)
Search Criteria
Package Details: ansible-language-server 1.2.3-1
Package Actions
| Git Clone URL: | https://aur.archlinux.org/ansible-language-server.git (read-only, click to copy) |
|---|---|
| Package Base: | ansible-language-server |
| Description: | Ansible Language Server |
| Upstream URL: | https://github.com/ansible/vscode-ansible/tree/main/packages/ansible-language-server |
| Licenses: | MIT |
| Submitter: | Antiz |
| Maintainer: | djugei |
| Last Packager: | Antiz |
| Votes: | 1 |
| Popularity: | 0.64 |
| First Submitted: | 2026-04-24 20:33 (UTC) |
| Last Updated: | 2026-06-11 17:11 (UTC) |
Dependencies (6)
- ansible
- nodejs (nodejs-gitAUR, nodejs-lts-hydrogenAUR, python-nodejs-wheelAUR, nodejs-lts-iron, nodejs-lts-jod, nodejs-lts-krypton)
- git (git-gitAUR, git-glAUR, git-wd40AUR) (make)
- yarn (yarn-berryAUR, yarn-corepackAUR) (make)
- ansible-lint (ansible-lint-gitAUR) (optional) – for Ansible linting support
- yamllint (optional) – for YAML linting support
Required by (1)
- helix-ext (optional)
Sources (1)
Latest Comments
Antiz commented on 2026-06-13 16:58 (UTC)
Antiz commented on 2026-06-13 10:34 (UTC) (edited on 2026-06-13 10:36 (UTC) by Antiz)
Alright, thanks! I'm AFK right now, I'll promote you as the maintainer later today or tomorrow ;)
djugei commented on 2026-06-13 10:30 (UTC)
yes i want to maintain this package, i will not drop the spot in the short term at least.
i have this installed from 2024, it was probably still in the repos back then, so i should probably take some responsibility for the package :D
Antiz commented on 2026-06-13 10:28 (UTC) (edited on 2026-06-13 10:29 (UTC) by Antiz)
I mean... I initially dropped the package to the AUR for a reason :p
To be precise, upstream integrated the language server to their vs code extension repo and it's now very tedious to package separately. I don't think there's much change to do to this package (unless you're willing fight against the new upstream distribution model). Again, I can promote you maintainer regardless if you really want to but please explicitly confirm your interest and avoid to disown it afterwards (at least until we could fully sort out the ongoing attack, otherwise the package might be infected again).
djugei commented on 2026-06-13 10:16 (UTC) (edited on 2026-06-13 11:03 (UTC) by djugei)
https://github.com/ansible/vscode-ansible/blob/main/packages/ansible-language-server/changelog.md seeing that the package has not had an upstream update in 2 years i guess i could manage that maintainance burden :D
edit: there have been changes/new releases, they just have not added those to the changelog.
Antiz commented on 2026-06-13 10:14 (UTC) (edited on 2026-06-13 10:15 (UTC) by Antiz)
Yes, that's intended for now. Force disowning the package would allow another malicious bot account to immediately adopt it and re-push the malware. The attack is automated, so we should avoid orphaning packages for now. If you're interested to pick up this package let me know though.
djugei commented on 2026-06-13 10:09 (UTC)
it seems like the malicious user (while banned) is still set as the maintainer of the package (+ i did a bit of research)
Antiz commented on 2026-06-13 09:59 (UTC)
@djugei Yes, I reverted / deleted the latest malicious commit pushed as part of the attack and banned the associated AUR account.
djugei commented on 2026-06-13 09:46 (UTC) (edited on 2026-06-13 10:07 (UTC) by djugei)
the git history of this package seems to have been altered, i would assume due to the attack, would it be possible to see the removed commit(s)?
edit: found it! https://github.com/archlinux/aur/compare/5854855f61c3cef1ce67e0586f7745fd1348cfe7...03d920918d17c569a91fb4dbe7a2a59b10aa9063
as the version of the package was not bumped during the attack, you would only be affected if you installed, or re-installed the package between june 11th and june 12th, if you have an older installation you are fine, and would not even have been prompted to update if you use an aur helper.
Pinned Comments
djugei commented on 2026-06-13 09:46 (UTC) (edited on 2026-06-13 10:07 (UTC) by djugei)
the git history of this package seems to have been altered, i would assume due to the attack, would it be possible to see the removed commit(s)?
edit: found it! https://github.com/archlinux/aur/compare/5854855f61c3cef1ce67e0586f7745fd1348cfe7...03d920918d17c569a91fb4dbe7a2a59b10aa9063
as the version of the package was not bumped during the attack, you would only be affected if you installed, or re-installed the package between june 11th and june 12th, if you have an older installation you are fine, and would not even have been prompted to update if you use an aur helper.