Package Details: turtl 0.7.2.6-1

Git Clone URL: https://aur.archlinux.org/turtl.git (read-only, click to copy)
Package Base: turtl
Description: The secure, collaborative notebook
Upstream URL: https://turtlapp.com/
Keywords: collaboration collaborative electron javascript note notebook notes rust secure turtl
Licenses: GPL3
Submitter: originof
Maintainer: neoninteger
Last Packager: neoninteger
Votes: 60
Popularity: 0.000000
First Submitted: 2016-02-03 15:32 (UTC)
Last Updated: 2019-06-05 09:09 (UTC)

Latest Comments

1 2 3 4 Next › Last »

neoninteger commented on 2022-03-21 03:46 (UTC)

I don't use clamAV, so I don't really know how its signature database works. I spent a bit of time just now reading about it, but none of the documentation I read was really helpful. (there's like, six different signature formats?)

The purpose of flagging a false positive is to alert the team that maintains the signature database that there might be a false positive - it is up to them (the Cisco Talos team if clamAV's documentation is correct) to manually review the information we provide and then perform the necessary modifications to the database, which may take several days if the team is busy.

If you know of other places where this could be escalated, that might help. But again, I don't use clamAV (I didn't even know it existed until yesterday :P) so I don't think I'll be of much help to you here.

romelsalwi commented on 2022-03-21 03:21 (UTC) (edited on 2022-03-21 03:22 (UTC) by romelsalwi)

Thanks for responding! @neoninteger! Why is this happening in the first place with clamAV? It came across few more files having the same signature. Should I escalate this to clamAV?

That false positive report didn't really helped

neoninteger commented on 2022-03-20 03:12 (UTC)

@romelsalwi I've just submitted the below report to clamAV's false positive report page, and I encourage you to do the same:

A user of my Arch Linux package for Turtl (an end-to-end-encrypted note-taking app written in JavaScript and Rust) reported that one of its dependencies (imurmurhash) is falsely flagged by clamAV as "PUA.Win.Trojan.Xored-1". According to the project's issue tracker (https://github.com/jensyt/imurmurhash-js/issues/1) this has been happening for at least two years now. This is an NPM package which currently sees over 25 million weekly downloads, and the SHA-256 checksum of the version included with the Turtl binary distribution (which I've attached below) matches that of the GitHub download (https://github.com/jensyt/imurmurhash-js/blob/master/imurmurhash.min.js) which is known to not have been tampered with.

romelsalwi commented on 2022-03-19 23:06 (UTC)

I just ran a clanAV scan on my system and found out imurmurhash.min.js is bugged with PUA.Win.Trojan.Xored-1 trojan

neoninteger commented on 2020-04-20 09:29 (UTC)

gconf is still needed, removing it from my system results in a dynamic linking error whenever I try to launch Turtl, specifically error while loading shared libraries: libgconf-2.so.4: cannot open shared object file: No such file or directory

It's probably possible to run Turtl without gconf however doing so would require building Turtl from source (probably with a newer Electron version, we're still using v1.8.3 here!) which I have yet to successfully accomplish. Remember that this package just pulls a prebuilt version of Turtl from GitHub Releases.

As for why I am unable to build from source, I'm running into https://github.com/turtl/tracker/issues/338 and https://github.com/turtl/tracker/issues/361

sebstar commented on 2020-04-19 11:00 (UTC)

BTW also agree that turtl should be renamed to turtl-bin.

sebstar commented on 2020-04-19 10:58 (UTC)

gconf is very outdated and is now in the AUR. Please check if turtl really still depends on gconf (it probably doesn't) and then remove it. Many other packages could already successfully remove gconf from their dependencies. Turtl is the only package remaining on my system why gconf is still pulled as a dep.

Rocky-IV commented on 2020-02-19 14:18 (UTC)

@neoninteger Thanks

neoninteger commented on 2020-02-19 04:02 (UTC)

v0.7.2.6-sqlite-fix appears to be a Mac-specific update, there's no Linux build for it that I can pull from. v0.7.2.6-pre-sync-fix appears to be the latest version for Linux.

Rocky-IV commented on 2020-02-18 22:07 (UTC)

@neoninteger: Newer Turtl release on Github - (v0.7.2.6-sqlite-fix) dated Nov 5, 2019