You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A malicious package could include files that are not tracked by eopkg. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown by lseopkg and related tools.
Warning
Installing packages from untrusted sources is never safe. While the files can now always be found using lseopkg, any file installed by the package manager has the potential to compromise your complete system. We strongly recommend using Flatpak to install 3rd party packages and only installing native Solus packages from sources you trust.
The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.
Learn more on MITRE.
Impact
A malicious package could include files that are not tracked by
eopkg. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown bylseopkgand related tools.Warning
Installing packages from untrusted sources is never safe. While the files can now always be found using
lseopkg, any file installed by the package manager has the potential to compromise your complete system. We strongly recommend using Flatpak to install 3rd party packages and only installing native Solus packages from sources you trust.Patches
The issue has been fixed in v4.4.0.
Workarounds
Users only installing packages from the Solus repositories are not affected.