4 ms·
> generally a better starting point than "well here is the source" Definitely not when it comes to security. We are talking about packages, which means even le
by rantanplan 9y ago
> generally a better starting point than "well here is the source"
Definitely not when it comes to security. We are talking about packages, which means even legit, well-intended programs can be weaponized by the packager.
That's a hell of an attack vector.
- jamespo 9y agolike COPR in fedora or PPA in ubuntu surely
- rantanplan 9y agoWhich I haven't ever used because I never needed them? (Talking about COPR, I don't use ubuntu). In contrast with AUR without which you don't have much of a useful desktop experience.
- Latty 9y agoThat's just not true. My desktop is Arch and I run maybe 5 or so AUR packages - and they are all for dev tools. You can definitely run a completely functional desktop without them.
- rantanplan 9y agoWell then, that's what I wanted to hear. Next thing would be for Arch to officially support SELinux and we're good to go :D
- rocqua 9y agoThere is a policy where, if an AUR package gets popular enough (I think it is around 15 'votes' in favor), it is added to the official repository. There are notable exceptions where the package license doesn't allow that. E.g. chrome (not chromium) spotify and dropbox.
- Latty 9y agoI meant more as in "as someone wanting to use something", rather than the security aspect. Most AUR packages I have seen have been incredibly easy to read - if you really don't want to use them, it's still a good framework for making your own packages much more easily, so you can install from source without dumping unmanaged stuff into your system.
- rantanplan 9y agoI think Debian has a better process in which they vet packagers. It's a bit more tedious but I'd put my trust more easily in such a system. > Most AUR packages I have seen have been incredibly easy to read It's not about quality, but rather more about quantity. I don't have the time to vet every package.
- striking 9y agoVetting a package is as easy as reading through its PKGBUILD. Here's a sample one: https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=pacaur https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=pacau... makepkg pulls source files and possibly patches, and then compiles them and installs them according to the instructions. It makes life simple.