Comment by charcircuit
5 hours ago
There are subtle things like abusing how github handles forks which can make malicious PKGBUILD a matter of just changing the rev with no hint in the file itself.
5 hours ago
There are subtle things like abusing how github handles forks which can make malicious PKGBUILD a matter of just changing the rev with no hint in the file itself.
Perhaps, but it would be pretty unusual to use a commit/hash id instead of a version tag, or the main development branch.