I've adopted this package given the potential abuse it could receive, and security implications.
I encourage any users of this, and other financial related AUR packages to diligently verify the legitimacy of packages.
Three checks you can do to help with this:
- Verify the source URL is pointing to the official Atomic Wallet domain.
- Visit the official Atomic Wallet website, download the rpm file, and confirm the SHA256 sum exactly matches what's stated in the PKGBUILD file.
- Note changes (diffs) that are pushed when the package is updated, for anything unusual.
Pinned Comments
Bink commented on 2024-07-25 04:19 (UTC) (edited on 2024-07-25 04:22 (UTC) by Bink)
I've adopted this package given the potential abuse it could receive, and security implications.
I encourage any users of this, and other financial related AUR packages to diligently verify the legitimacy of packages.
Three checks you can do to help with this: