I am surprised it took them so long. It would have been the first thing to do, block new users, stop people takeong over orphaned packages or make the whole AUR read only for a while. Any of those would have disrupted this attack and gave the devs more time to figure out a longer term solution.
I am surprised it took them so long. It would have been the first thing to do, block new users, stop people takeong over orphaned packages or make the whole AUR read only for a while. Any of those would have disrupted this attack and gave the devs more time to figure out a longer term solution.