6 ms·
Not a surprise.
by lerax 8y ago
Not a surprise.
- craftyguy 8y agoYes, but this may be a good reminder for fellow Arch users who have grown complacent reviewing things they install from AUR. I've gotten to the point where I do not install any AUR helpers on my systems, and manually download PKGBUILDs and install with makepkg. These extra steps force me to 1) review the PKGBUILD + *.install files, and 2) make me reconsider whether or not I want to go through the effort for a package (i.e. "do I really want this thing") If you want to see all software installed from outside repos defined in /etc/pacman.conf, you can use this pacman option: pacman -Qm It's always a good idea to periodically review this list as well.
- jolmg 8y agoI've seen the advice of not installing AUR helpers multiple times before. I guess it works for many, but I feel it takes more discipline to review the files when not using AUR helpers since you can just download them and makepkg them immediately, while all AUR helpers I've seen explicitly ask you if you'd like to first review the files in an editor with a default answer of [Y]es.
- craftyguy 8y ago> while all AUR helpers I've seen explicitly ask you if you'd like to first review the files in an editor The good ones do, yes. > with a default answer of [Y]es. And therein lies the problem. You may review a handful up front, but then convince yourself that all is good since it's much easier to just press 'enter' and move on. It's MUCH easier to ignore a PKGBUILD when you have to hit one key to skip it than it is if you have to manually download it, put it somewhere, and 'makepkg' on it.
- jolmg 8y agoI think you misread. Pressing 'enter' opens up the editor to review the files. To ignore them, you'd have to answer [n]o.
- craftyguy 8y agoAh, in that case, most I've come across do not default to 'edit', but rather to accept. Notice that many default to automatic building: https://wiki.archlinux.org/index.php/AUR_helpers#Active https://wiki.archlinux.org/index.php/AUR_helpers#Active
- jolmg 8y agoHuh. Thanks for the link; I hadn't realized that pacaur was announced unmaintained last December. I'll have to look for a replacement.
- imtringued 8y agoaurman is the best replacement
- bscphil 8y agoThe developer of pacaur now works on auracle.
- Foxboron 8y agoFalconindy is not the developer of pacaur.
- cakes 8y agoOne of the problem I see with helpers is that a lot of them start to wrap the whole user's package handling experience (pacman wrapping) where it seems like it would be easy to ignore the prompts and "just download the package already". You can tell users the AUR is unsafe and to review PKGBUILDs but that doesn't mean they are going to listen or do it. I did write a helper, mainly for myself and a few other arch users I know, and if not for having completed it enough to use it, I wouldn't do it again (I don't support pacman wrapping). I use like 5-10 packages from the AUR and I either maintain them or they _never_ change and I would know something is wrong. The other point to this is how is this sort of compromise best communicated? It's important enough to hit [0] and obviously this news site, the mailinglist[1], but not the frontpage of arch itself. [0] planet.archlinux.org [1] https://lists.archlinux.org/pipermail/aur-general/2018-July/034151.html https://lists.archlinux.org/pipermail/aur-general/2018-July/...
- Foxboron 8y ago> The other point to this is how is this sort of compromise best communicated? It's important enough to hit [0] and obviously this news site, the mailinglist[1], but not the frontpage of arch itself. I brought it up partially, and the simple explanation is; We don't. It's unsupported and compromised packages happens. There is no system in place to warn about it and the frontpage is reserved for news about issues regarding official packages.