Package Details: python-vincenty 0.1.4-2

Git Clone URL: https://aur.archlinux.org/python-vincenty.git (read-only, click to copy)
Package Base: python-vincenty
Description: Calculates geographical distance between 2 points with extreme accuracy
Upstream URL: https://github.com/maurycyp/vincenty
Keywords: python vincenty
Licenses: Unlicense
Submitter: bananaboydean
Maintainer: eduardmaskova
Last Packager: tippfehlr
Votes: 8
Popularity: 0.000000
First Submitted: 2016-01-23 20:03 (UTC)
Last Updated: 2026-06-11 15:26 (UTC)

Dependencies (5)

Required by (0)

Sources (1)

Latest Comments

maxweiss commented on 2026-06-13 01:53 (UTC)

@Syslogista this package was part of the recent AUR malware campaign which installed a malicious npm package via an install script. It appears that that has been fixed, so the package is currently safe. However the listed maintainer "eduardmaskova" is a malicious threat actor, and you should hold/pin the package after you install a safe version until you have confirmed a more trustworthy maintainer owns it.

Sylogista commented on 2026-06-12 13:30 (UTC)

@maxweiss For me everything looks fine. What makes you think this is a virus? Where is the danger in your opinion?

It's importing math and doctest, nothing more. It's a single function. No operation on files, no network traffic, and no execution of arbitrary binaries.

maxweiss commented on 2026-06-11 15:08 (UTC) (edited on 2026-06-13 01:53 (UTC) by maxweiss)

THIS IS A VIRUS, DO NOT INSTALL

Edit: the package now appears safe again. See my more recent comment.

NicoHood commented on 2018-11-10 14:44 (UTC)

@wickdchromosome could you please follow my suggestions? It adds support for python2, proper license files and includes common fixes.

wsduvall commented on 2017-11-03 00:51 (UTC)

Whoever takes this over, please change to https in the source.

svenstaro commented on 2017-10-28 23:44 (UTC)

Orphaning this. Someone take this over.

ninov commented on 2017-10-28 09:57 (UTC)

Please change source address in PKGBUILD to https. Otherwise it won't be downloaded by makepkg.

NicoHood commented on 2017-09-18 18:55 (UTC)

PKGBUILD suggestion: https://gist.github.com/NicoHood/de796cb1bff3e6a61e6676453d2cca8f