3 ms·
I think the wrongful notion comes from the fact that the vast majority of Arch users use and speak about AUR as if it were a part of arch proper, only paying li
by davkan 2mo ago
I think the wrongful notion comes from the fact that the vast majority of Arch users use and speak about AUR as if it were a part of arch proper, only paying lip service to reviewing PKGBUILDS, etc. They wrap the default package manager in one that supports AUR and never touch it directly again. It feels closer to if all of GitHub was available in one click through the Microsoft store or windows update.
And unfortunately that’s how arch is mainly marketed by its users. “Arch has the latest everything, if it’s not in the repos it’s on AUR” is one of the standard selling points.
Of course that speaks to how people use linux insecurely not how Linux is insecure.
- thayne 2mo agoMost AUR "helpers" show you the PKGBUILD and/or a diff thereof and ask you to confirm that it looks ok before continuing the install. At least by default. Maybe most users just ignore that and always answer yes without inspecting it. I don't know. But the wiki for the AUR and Readmes for many of these tools have warning banners telling you not to blindly trust AUR packages.
- charcircuit 2mo agoThere are subtle things like abusing how github handles forks which can make malicious PKGBUILD a matter of just changing the rev with no hint in the file itself.
- thayne 2mo agoPerhaps, but it would be pretty unusual to use a commit/hash id instead of a version tag, or the main development branch.
- LargoLasskhyfv 2mo agoThere is much stuff which isn't in the AUR at all, or if so in versions similar to debian default, and/or orphaned. Nonetheless, the full tray is just one yay away, which also speaks git. How you use such tools is totally up to you. So far I've been unaffected by the AUR hickups, running Cachy for about 2 years now. But I've been always wary about the AUR, trying to minimize its use. Even in the phase where I used pure Arch for several years. It tends to get messy. So less AUR is less mess.