4 ms·
I trust packages that comes from official repositories. > Warning: AUR packages are user produced content. These PKGBUILDs are completely unofficial and have n
by sergeykish 6y ago
I trust packages that comes from official repositories.
> Warning: AUR packages are user produced content. These PKGBUILDs are completely unofficial and have not been thoroughly vetted. Any use of the provided files is at your own risk.
In other words AUR is not much safer than `curl to | sh`.
- gchamonlive 6y agoSure, but it is centralised in the os distribution package manager, if you use helpers like yay. I am just pointing out that centralisation is not solution to the attack mentioned.
- NullPrefix 6y agoI assume AUR includes hashes, which could at least hint to deterministic builds. `curl to | sh` can change from build to build and there's no way to find out from which source other users built.