More info in Mastodon post: <a href=“https://gaysex.cloud/notes/andaxow7itfn05x9” rel=“ugc”>https://gaysex.cloud/notes/andaxow7itfn05x9</a> List of affected packages: <a href=“https://gr.ht/aur_pkg_list.txt” rel=“ugc”>https://gr.ht/aur_pkg_list.txt</a> Comments
That link in the OP is clouding my judgement if the link is safe or not.
Man, that’s a lot of python.
EDIT: No, sorry, I misread the article. The commits were made to a large number of packages, alvr was just one of many.
If I’m not mistaken users can simply type “pacman -Q | grep alvr” and if there are no results or the result is before the update then they’re good? Also check to make sure the command works with something like “pacman -Q | grep curl” or other package you know is installed.


