AUR Audit Integration

Pager review versus enforced gate

AUR Audit Integration Pager review versus enforced gate EX / Before aur-audit 02 / After aur-audit Fetch repo · Before aur-audit Fetch repo Human review · pager · Before aur-audit Human review pager makepkg runs · Before aur-audit makepkg runs Compromised · Before aur-audit · risk Compromised risk Fetch repo · After aur-audit Fetch repo PreBuild hook · After aur-audit PreBuild hook aur-audit scan · static checks · After aur-audit · gate aur-audit scan static checks gate Abort build · After aur-audit Abort build makepkg runs · After aur-audit makepkg runs Secure install · After aur-audit · done Secure install done confirms malicious threat clean Legend Agent logic Policy External system

Before

  • • Pager review, then build runs
  • • Malicious code reaches the host

After

  • • Pre-build audit gates the build
  • • Threat halts before makepkg