Not going to repeat everything word for word, but Manjaros in house package manager pamac, has a major security flaw by allowing any packages from anywhere be installed WITHOUT asking for any password permissions.
The original thread is linked below.
https://forum.manjaro.org/t/should-i-be-concerned-if-one-of-my-manjaro-installs-is-updating-without-requiring-a-sudo-password/117999
The original thread is linked below.
https://forum.manjaro.org/t/should-i-be-concerned-if-one-of-my-manjaro-installs-is-updating-without-requiring-a-sudo-password/117999
Comment