4 ms·
Many packages are _way_ more complex than 3-5 lines to review. To take an example (perhaps a bit extreme, but realistic as many nVidia users _have_ to install i
by kalenx 2mo ago
Many packages are _way_ more complex than 3-5 lines to review. To take an example (perhaps a bit extreme, but realistic as many nVidia users _have_ to install it), check nvidia-580xx-dkms
Every patch (which runs in kernel space) may of course contain backdoors, so you'd have to review them. Every install line in the PKGBUILD may be installing a malware.
Of course it is _possible_ to review all of it, but clearly not simple, even for a fairly technical user.
Sure, if you assume that every attack would be as glaring as the ones we've seen before, that makes it easier. But think of an attack at the level of the xz one and virtually no one would catch it.