{"id":57437,"date":"2025-11-14T20:37:43","date_gmt":"2025-11-14T18:37:43","guid":{"rendered":"https:\/\/cryptrz.org\/wordpress\/?p=57437"},"modified":"2025-11-14T21:11:19","modified_gmt":"2025-11-14T19:11:19","slug":"comment-verifier-les-pkgbuilds-darch-linux","status":"publish","type":"post","link":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/","title":{"rendered":"Comment v\u00e9rifier les PKGBUILDs d&rsquo;Arch Linux"},"content":{"rendered":"\n<p>Ces derniers temps, <a href=\"https:\/\/lists.archlinux.org\/archives\/list\/aur-general@lists.archlinux.org\/thread\/7EZTJXLIAQLARQNTMEW2HBWZYE626IFJ\/\" target=\"_blank\" rel=\"noreferrer noopener\">plusieurs logiciels malicieux<\/a> ont fait leur apparition sur l&rsquo;<a href=\"https:\/\/aur.archlinux.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">AUR<\/a> (Arch User Repository) d&rsquo;<a href=\"https:\/\/fr.wikipedia.org\/wiki\/Arch_Linux\" target=\"_blank\" rel=\"noreferrer noopener\">Arch Linux<\/a>. Des versions v\u00e9rol\u00e9es de <a href=\"https:\/\/lists.archlinux.org\/archives\/list\/aur-general@lists.archlinux.org\/thread\/7EZTJXLIAQLARQNTMEW2HBWZYE626IFJ\/\" target=\"_blank\" rel=\"noreferrer noopener\">Librewolf. Firefox, Zen Browser<\/a> et <a href=\"https:\/\/www.techprovidence.com\/aur-fake-chrome-package-rat\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chrome<\/a> ont \u00e9t\u00e9 upload\u00e9es dans l&rsquo;espoir que les personnes les plus n\u00e9gligentes qui ne v\u00e9rifient pas les <a href=\"https:\/\/wiki.archlinux.org\/title\/PKGBUILD_(Fran%C3%A7ais)\" target=\"_blank\" rel=\"noreferrer noopener\">PKGBUILDs<\/a> installent ces joli <a href=\"https:\/\/www.malekal.com\/rat-remote-access-tool-botnet\/\" target=\"_blank\" rel=\"noreferrer noopener\">RAT<\/a>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png\" alt=\"\" class=\"wp-image-59688\" srcset=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png 1024w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check-300x168.png 300w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check-768x431.png 768w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check-990x556.png 990w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p>Les utilisateurs et contributeurs d&rsquo;<a href=\"https:\/\/archlinux.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">Arch Linux<\/a> ont souvent la r\u00e9putation d&rsquo;\u00eatre \u00e9litistes, mais il n&rsquo;en est rien. r\u00e9ussir \u00e0 installer Arch est une chose, mais une fois install\u00e9, il reste d\u00e9j\u00e0 <a href=\"https:\/\/cryptrz.org\/wordpress\/2025\/10\/15\/5-choses-a-faire-apres-avoir-installe-arch-linux\/\" target=\"_blank\" rel=\"noreferrer noopener\">quelques \u00e9tapes de base<\/a> \u00e0 ne pas oublier. Mais ces exemples d&rsquo;attaques montrent surtout qu&rsquo;il est pr\u00e9f\u00e9rable d&rsquo;avoir un minimum de connaissance en programnation <a href=\"https:\/\/frederic-lang.developpez.com\/tutoriels\/linux\/prog-shell\/\" target=\"_blank\" rel=\"noreferrer noopener\">Shell<\/a> pour v\u00e9rifier ce qu&rsquo;on installe. Piocher \u00e0 l&rsquo;aveugle dans les repo <strong>AUR<\/strong> revient \u00e0 se ballader \u00e0 poil devant un essaim d&rsquo;abeilles (On peut toujours utiliser <strong>Arch<\/strong> sans <strong>AUR<\/strong> mais on limite fortement le nombre de packages disponibles).<\/p>\n\n\n\n<p>Si besoin, pour pouvoir mieux profiter de Arch, explorez le monde merveilleux du shell et de la structure de <a href=\"https:\/\/fr.wikipedia.org\/wiki\/Linux\" target=\"_blank\" rel=\"noreferrer noopener\">Linux<\/a>. Voici quelques exemples de tutos:<\/p>\n\n\n\n<p>Pour d\u00e9buter en Bash script:<br><a href=\"https:\/\/www.it-connect.fr\/debuter-script-bash-linux\/\" target=\"_blank\" rel=\"noreferrer noopener\">Introduction au script Bash sous Linux : cr\u00e9er son premier script !<\/a><\/p>\n\n\n\n<p>La documentation officielle pour PKGBUILD:<br><a href=\"https:\/\/wiki.archlinux.org\/title\/PKGBUILD_(Fran%C3%A7ais)\" target=\"_blank\" rel=\"noreferrer noopener\">PKGBUILD<\/a><\/p>\n\n\n\n<p>Pour aller plus loin en Bash: <br><a href=\"https:\/\/frederic-lang.developpez.com\/tutoriels\/linux\/prog-shell\/\" target=\"_blank\" rel=\"noreferrer noopener\">La programmation \u00ab\u00a0Shell\u00a0\u00bb<\/a> <\/p>\n\n\n\n<p>Pour d\u00e9couvrir l&rsquo;archtecture d&rsquo;un syst\u00e8me Linux et l&rsquo;analyser:<br><a href=\"https:\/\/cryptrz.org\/wordpress\/2024\/11\/28\/comment-investiguer-une-machine-sous-linux\/\" target=\"_blank\" rel=\"noreferrer noopener\">Comment investiguer une machine sous Linux<\/a><br><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"pourquoi-vrifier\">Pourquoi v\u00e9rifier ?<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Les PKGBUILD sont des <strong>scripts shell<\/strong> ex\u00e9cut\u00e9s avec vos droits utilisateur.<\/li>\n\n\n\n<li>Ils peuvent t\u00e9l\u00e9charger et ex\u00e9cuter n&rsquo;importe quel code.<\/li>\n\n\n\n<li>Un <strong>PKGBUILD<\/strong> malveillant peut compromettre votre syst\u00e8me.<\/li>\n\n\n\n<li>M\u00eame des <strong>PKGBUILDs<\/strong> bien intentionn\u00e9s peuvent contenir des erreurs.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"processus-de-revue-basique\">Processus de revue basique<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Lire le fichier PKGBUILD<\/strong><br>Apr\u00e8s avoir clon\u00e9 depuis l\u2019AUR : <code>git clone https:\/\/aur.archlinux.org\/nom-du-paquet.git cd nom-du-paquet cat PKGBUILD # ou utilisez votre \u00e9diteur pr\u00e9f\u00e9r\u00e9<\/code><\/li>\n\n\n\n<li><strong>V\u00e9rifier ce qui est t\u00e9l\u00e9charg\u00e9<\/strong>\n<ul class=\"wp-block-list\">\n<li>Regardez le tableau <code>source<\/code> : <code>grep \"^source=\" PKGBUILD<\/code><\/li>\n\n\n\n<li>V\u00e9rifiez la pr\u00e9sence de sommes de contr\u00f4le (\u00e9vitez <code>SKIP<\/code>) : <code>grep \"sha256sums=\" PKGBUILD<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Inspecter les fichiers additionnels<\/strong>\n<ul class=\"wp-block-list\">\n<li>Lister pour trouver des scripts <code>.install<\/code> ou des patchs : <code>ls -la cat *.install # pour voir les scripts d\u2019installation\/mise \u00e0 jour<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Les red flags <\/h2>\n\n\n\n<p>Patterns dangereux :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>curl | sh<\/code> (pipe vers le shell)<\/li>\n\n\n\n<li><code>wget -O- | bash<\/code><\/li>\n\n\n\n<li><code>rm -rf \/<\/code> ou <code>$HOME<\/code> (suppression destructrice)<\/li>\n\n\n\n<li><code>chmod 777<\/code> (droits excessifs)<\/li>\n\n\n\n<li><code>sudo<\/code> dans <code>build()<\/code> (jamais n\u00e9cessaire)<\/li>\n\n\n\n<li><code>eval $(curl ...)<\/code> (ex\u00e9cution \u00e0 distance)<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Comportements suspects<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>source=()<\/code> contenant des URLs non fiables ou du HTTP non s\u00e9curis\u00e9<\/li>\n\n\n\n<li>Sommes de contr\u00f4le manquantes ou en <code>SKIP<\/code><\/li>\n\n\n\n<li>Code obfusqu\u00e9 ou commandes encod\u00e9es en base64<\/li>\n\n\n\n<li>T\u00e9l\u00e9chargements depuis pastebin ou raccourcisseurs d\u2019URL<\/li>\n\n\n\n<li>Activit\u00e9 r\u00e9seau sortant du cadre du t\u00e9l\u00e9chargement de sources<\/li>\n\n\n\n<li>\u00c9criture vers des r\u00e9pertoires syst\u00e8me dans <code>build()<\/code><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Signes positifs <\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Code clair, lisible<\/li>\n\n\n\n<li>Sources HTTPS provenant de d\u00e9p\u00f4ts officiels<\/li>\n\n\n\n<li>Pr\u00e9sence de sommes sha256\/sha512<\/li>\n\n\n\n<li>Mainteneur reconnu ou contributeur officiel<\/li>\n\n\n\n<li>Mises \u00e0 jour r\u00e9centes<\/li>\n\n\n\n<li>Populaire\/vot\u00e9 sur l\u2019AUR<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"outils-de-revue\">Outils de revue<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>namcap<\/strong> : v\u00e9rifier le PKGBUILD <code>namcap PKGBUILD<\/code><\/li>\n\n\n\n<li><strong>V\u00e9rifier la page AUR<\/strong>\n<ul class=\"wp-block-list\">\n<li>Lire les commentaires<\/li>\n\n\n\n<li>Regarder le nombre de votes\/popularit\u00e9<\/li>\n\n\n\n<li>Observer l\u2019historique du mainteneur, l\u2019\u00e2ge et la derni\u00e8re mise \u00e0 jour du paquet<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Comparer avec les paquets officiels<\/strong>\n<ul class=\"wp-block-list\">\n<li>Si un \u00e9quivalent existe : <code>asp export paquet-officiel diff -u paquet-officiel\/PKGBUILD votre-paquet\/PKGBUILD<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Voir l\u2019historique git :<\/strong> <code>git log --all --oneline git show &lt;commit><\/code><\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"checklist-revue-tape-par-tape\">Checklist revue \u00e9tape par \u00e9tape<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Examiner les m\u00e9tadonn\u00e9es : <code>head -n 20 PKGBUILD<\/code><\/li>\n\n\n\n<li>V\u00e9rifier les sources : <code>grep -A 5 \"^source=\" PKGBUILD<\/code><\/li>\n\n\n\n<li>V\u00e9rifier que les sommes de contr\u00f4le ne sont pas en SKIP : <code>grep \"sums=\" PKGBUILD<\/code><\/li>\n\n\n\n<li>Revoir la fonction <code>build()<\/code> : <code>sed -n '\/^build()\/,\/^}\/p' PKGBUILD<\/code><\/li>\n\n\n\n<li>Revoir la fonction <code>package()<\/code> : <code>sed -n '\/^package()\/,\/^}\/p' PKGBUILD<\/code><\/li>\n\n\n\n<li>V\u00e9rifier la pr\u00e9sence de scripts install : <code>cat *.install 2>\/dev\/null<\/code><\/li>\n\n\n\n<li>V\u00e9rifier avec namcap : <code>namcap PKGBUILD<\/code><\/li>\n\n\n\n<li>Lire les commentaires sur l\u2019AUR.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"tester-dans-un-environnement-isol-avanc\">Tester dans un environnement isol\u00e9 (avanc\u00e9)<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Chroot propre<\/strong> : <code>extra-x86_64-build<\/code><\/li>\n\n\n\n<li><strong>Avec Docker\/Podman<\/strong> : <code>docker run -it archlinux bash # installer et tester le paquet \u00e0 l\u2019int\u00e9rieur<\/code><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"problmes-courants--reprer\">Probl\u00e8mes courants \u00e0 rep\u00e9rer<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>D\u00e9pendances manquantes (<code>depends=()<\/code>)<\/li>\n\n\n\n<li><code>pkgver<\/code> incorrect<\/li>\n\n\n\n<li>Chemins cod\u00e9s en dur au lieu de variables (<code>$pkgdir<\/code>, <code>$srcdir<\/code>)<\/li>\n\n\n\n<li>Licence absente<\/li>\n\n\n\n<li>Sp\u00e9cification d&rsquo;architecture incorrecte (<code>arch=()<\/code>)<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"exemple-de-revue\">Exemple de revue<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Cloner et se placer dans le dossier : <code>git clone https:\/\/aur.archlinux.org\/spotify.git cd spotify<\/code><\/li>\n\n\n\n<li>Aper\u00e7u rapide : <code>cat PKGBUILD | head -20<\/code><\/li>\n\n\n\n<li>V\u00e9rifier sources et checksums : <code>grep -E \"(source|sums)=\" PKGBUILD<\/code><\/li>\n\n\n\n<li>Chercher les patterns dangereux : <code>grep -i \"curl.*sh\\|wget.*bash\\|rm -rf\\|sudo\" PKGBUILD<\/code><\/li>\n\n\n\n<li>V\u00e9rifier avec namcap : <code>namcap PKGBUILD<\/code><\/li>\n\n\n\n<li>Si c\u2019est bon, compiler : <code>makepkg -si<\/code><\/li>\n<\/ol>\n\n\n\n<p>Avec ces quelques v\u00e9rifications en t\u00eate, vous voyez maintenant qu&rsquo;il est assez facile de d\u00e9tecter la tentative d&rsquo;attaque de \u00ab\u00a0google-chrome-stable\u00a0\u00bb dont on parlait en intro: <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"788\" height=\"498\" src=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/aur-google-chrome-stable.png\" alt=\"\" class=\"wp-image-59683\" srcset=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/aur-google-chrome-stable.png 788w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/aur-google-chrome-stable-300x190.png 300w, https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/aur-google-chrome-stable-768x485.png 768w\" sizes=\"auto, (max-width: 788px) 100vw, 788px\" \/><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"bonnes-pratiques\">Bonnes pratiques<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ne jamais faire confiance aveugl\u00e9ment, m\u00eame aux paquets populaires<\/li>\n\n\n\n<li>Mettre \u00e0 jour r\u00e9guli\u00e8rement, et revoir les changements (<code>git diff<\/code>)<\/li>\n\n\n\n<li>Signaler les probl\u00e8mes (laisser des commentaires sur l\u2019AUR)<\/li>\n\n\n\n<li>Utiliser les helpers AUR (yay, paru&#8230;) avec prudence et toujours afficher le PKGBUILD pour contr\u00f4le<\/li>\n\n\n\n<li>En cas de doute, demander conseil sur le forum Arch ou IRC<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Astuce AUR helpers<\/h2>\n\n\n\n<p>Avec yay, paru, etc&#8230;<\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/Jguer\/yay\" target=\"_blank\" rel=\"noreferrer noopener\">yay<\/a>:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><code>yay -S nom-du-paquet  # Affiche le PKGBUILD pour revue avant installation<br>yay -Gp nom-du-paquet  # Affiche seulement le PKGBUILD sans installer<br><\/code><\/pre>\n\n\n\n<p>Et <a href=\"https:\/\/github.com\/Morganamilo\/paru\">paru<\/a> l&rsquo;affiche par d\u00e9faut. <\/p>\n\n\n\n<p class=\"has-red-color has-text-color has-link-color wp-elements-3d30cc6b09b21aca3a8fad3244eec3c9\"><strong>R\u00e8gle d\u2019or : si vous ne comprenez pas le contenu d\u2019un PKGBUILD, ne l\u2019ex\u00e9cutez pas tant que vous n\u2019avez pas compris ou qu\u2019une personne de confiance (donc pas un mec random sur jeuxvideo.com) ne l\u2019a pas valid\u00e9.<\/strong><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ces derniers temps, plusieurs logiciels malicieux ont fait leur apparition sur l&rsquo;AUR (Arch User Repository) d&rsquo;Arch Linux. Des versions v\u00e9rol\u00e9es de Librewolf. Firefox, Zen Browser et Chrome ont \u00e9t\u00e9 upload\u00e9es<a href=\"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/\" class=\"more-link\"><span class=\"readmore\">Continue reading<span class=\"screen-reader-text\">Comment v\u00e9rifier les PKGBUILDs d&rsquo;Arch Linux<\/span><\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[165,105,136],"tags":[201,212,53,59],"class_list":["post-57437","post","type-post","status-publish","format-standard","hentry","category-investigation","category-linux","category-pratique","tag-arch","tag-archlinux","tag-code","tag-tutoriel"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Comment v\u00e9rifier les PKGBUILDs d&#039;Arch Linux &#8226; Cryptrz<\/title>\n<meta name=\"description\" content=\"Il est important de TOUJOURS v\u00e9rifier un PKGBUILD avant d&#039;installer un logiciel de AUR. Voyons comment proc\u00e9der.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Comment v\u00e9rifier les PKGBUILDs d&#039;Arch Linux &#8226; Cryptrz\" \/>\n<meta property=\"og:description\" content=\"Il est important de TOUJOURS v\u00e9rifier un PKGBUILD avant d&#039;installer un logiciel de AUR. Voyons comment proc\u00e9der.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptrz\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-14T18:37:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-14T19:11:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"575\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"cryptrz\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"cryptrz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/\"},\"author\":{\"name\":\"cryptrz\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\"},\"headline\":\"Comment v\u00e9rifier les PKGBUILDs d&rsquo;Arch Linux\",\"datePublished\":\"2025-11-14T18:37:43+00:00\",\"dateModified\":\"2025-11-14T19:11:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/\"},\"wordCount\":769,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\"},\"image\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/arch-PKGBUILD-check.png\",\"keywords\":[\"arch\",\"archlinux\",\"code\",\"tutoriel\"],\"articleSection\":[\"Investigation\",\"Linux\",\"Pratique\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/\",\"name\":\"Comment v\u00e9rifier les PKGBUILDs d'Arch Linux &#8226; Cryptrz\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/arch-PKGBUILD-check.png\",\"datePublished\":\"2025-11-14T18:37:43+00:00\",\"dateModified\":\"2025-11-14T19:11:19+00:00\",\"description\":\"Il est important de TOUJOURS v\u00e9rifier un PKGBUILD avant d'installer un logiciel de AUR. Voyons comment proc\u00e9der.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/arch-PKGBUILD-check.png\",\"contentUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/arch-PKGBUILD-check.png\",\"width\":1024,\"height\":575},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/2025\\\/11\\\/14\\\/comment-verifier-les-pkgbuilds-darch-linux\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Comment v\u00e9rifier les PKGBUILDs d&rsquo;Arch Linux\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#website\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/\",\"name\":\"Cryptrz\",\"description\":\"Franck Ridel\",\"publisher\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\"},\"alternateName\":\"Franck Ridel\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/#\\\/schema\\\/person\\\/24ebe8f2cc302fa3336ab7509a09b7ec\",\"name\":\"cryptrz\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\",\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\",\"contentUrl\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\",\"width\":1024,\"height\":1024,\"caption\":\"cryptrz\"},\"logo\":{\"@id\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/cover-design.jpg\"},\"description\":\"Sysadmin de Luxembourg House of Cybersecurity fan d'open source et autres Unixeries\",\"sameAs\":[\"https:\\\/\\\/cryptrz.org\\\/wordpress\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/franck-ridel\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@FranckRidel\",\"https:\\\/\\\/soundcloud.com\\\/franck-ridel-2\"],\"url\":\"https:\\\/\\\/cryptrz.org\\\/wordpress\\\/author\\\/cryptrz\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Comment v\u00e9rifier les PKGBUILDs d'Arch Linux &#8226; Cryptrz","description":"Il est important de TOUJOURS v\u00e9rifier un PKGBUILD avant d'installer un logiciel de AUR. Voyons comment proc\u00e9der.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/","og_locale":"fr_FR","og_type":"article","og_title":"Comment v\u00e9rifier les PKGBUILDs d'Arch Linux &#8226; Cryptrz","og_description":"Il est important de TOUJOURS v\u00e9rifier un PKGBUILD avant d'installer un logiciel de AUR. Voyons comment proc\u00e9der.","og_url":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/","og_site_name":"Cryptrz","article_published_time":"2025-11-14T18:37:43+00:00","article_modified_time":"2025-11-14T19:11:19+00:00","og_image":[{"width":1024,"height":575,"url":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png","type":"image\/png"}],"author":"cryptrz","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"cryptrz","Dur\u00e9e de lecture estim\u00e9e":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#article","isPartOf":{"@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/"},"author":{"name":"cryptrz","@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec"},"headline":"Comment v\u00e9rifier les PKGBUILDs d&rsquo;Arch Linux","datePublished":"2025-11-14T18:37:43+00:00","dateModified":"2025-11-14T19:11:19+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/"},"wordCount":769,"commentCount":0,"publisher":{"@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec"},"image":{"@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png","keywords":["arch","archlinux","code","tutoriel"],"articleSection":["Investigation","Linux","Pratique"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/","url":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/","name":"Comment v\u00e9rifier les PKGBUILDs d'Arch Linux &#8226; Cryptrz","isPartOf":{"@id":"https:\/\/cryptrz.org\/wordpress\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#primaryimage"},"image":{"@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png","datePublished":"2025-11-14T18:37:43+00:00","dateModified":"2025-11-14T19:11:19+00:00","description":"Il est important de TOUJOURS v\u00e9rifier un PKGBUILD avant d'installer un logiciel de AUR. Voyons comment proc\u00e9der.","breadcrumb":{"@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#primaryimage","url":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png","contentUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2025\/11\/arch-PKGBUILD-check.png","width":1024,"height":575},{"@type":"BreadcrumbList","@id":"https:\/\/cryptrz.org\/wordpress\/2025\/11\/14\/comment-verifier-les-pkgbuilds-darch-linux\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/cryptrz.org\/wordpress\/"},{"@type":"ListItem","position":2,"name":"Comment v\u00e9rifier les PKGBUILDs d&rsquo;Arch Linux"}]},{"@type":"WebSite","@id":"https:\/\/cryptrz.org\/wordpress\/#website","url":"https:\/\/cryptrz.org\/wordpress\/","name":"Cryptrz","description":"Franck Ridel","publisher":{"@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec"},"alternateName":"Franck Ridel","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptrz.org\/wordpress\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":["Person","Organization"],"@id":"https:\/\/cryptrz.org\/wordpress\/#\/schema\/person\/24ebe8f2cc302fa3336ab7509a09b7ec","name":"cryptrz","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg","url":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg","contentUrl":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg","width":1024,"height":1024,"caption":"cryptrz"},"logo":{"@id":"https:\/\/cryptrz.org\/wordpress\/wp-content\/uploads\/2024\/09\/cover-design.jpg"},"description":"Sysadmin de Luxembourg House of Cybersecurity fan d'open source et autres Unixeries","sameAs":["https:\/\/cryptrz.org\/wordpress","https:\/\/www.linkedin.com\/in\/franck-ridel\/","https:\/\/www.youtube.com\/@FranckRidel","https:\/\/soundcloud.com\/franck-ridel-2"],"url":"https:\/\/cryptrz.org\/wordpress\/author\/cryptrz\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts\/57437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/comments?post=57437"}],"version-history":[{"count":6,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts\/57437\/revisions"}],"predecessor-version":[{"id":59690,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/posts\/57437\/revisions\/59690"}],"wp:attachment":[{"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/media?parent=57437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/categories?post=57437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptrz.org\/wordpress\/wp-json\/wp\/v2\/tags?post=57437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}