[pacman-dev] makepkg security
Xyne
xyne at archlinux.ca
Sat Jul 11 06:29:11 EDT 2009
> The original complaint was that when using makepkg -sic, the sudo
> password is cached after dependency installation and malicious sudo
> commands might be executed during build() as the password is cached.
>
> My opinion on this is that we should not encourage people to use sudo,
> Aaron suggested to move it here for further discussion. What do you think?
Couldn't you just add an option to kill sudo after dependency installation?
More information about the pacman-dev
mailing list