Critical-risk tools in Arch Linux
2 of the 22 tools in Arch Linux are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
remove_packagesDestructive[LIFECYCLE] Unified tool for removing packages (single or multiple). Accepts either a single package name or a list of packages. Supports removal with dependencies and forced re...
-
manage_orphansDestructive[MAINTENANCE] Unified tool for managing orphaned packages (dependencies no longer required). Supports two actions:
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.