this post was submitted on 01 Aug 2025
84 points (93.8% liked)

Linux

8723 readers
468 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] h4x0r@lemmy.dbzer0.com 11 points 21 hours ago (1 children)

Why does anything need to change? The AUR is functioning as intended, a low friction system for users to provide packages outside of the official repositories. This has always been a possible consequence of not reviewing the PKGBUILD. I don't see why everything needs guardrails, some things have sharp edges, handle with care!

Given how often the 'btw' spammers evangelize how they learned soooo much about linux and their 'minimal system' cause they managed to format a disk manually and chroot, not installing malware from an untrusted source ought to be a no brainer. Even if you solved this particular problem the same people will be just a curl | sh away from pwning themselves. Should we start requiring forced auth to pipe?

The maintainers are welcome to do whatever they like, but it would be nice to have at least a few places where we don't cater to the lowest common denominator and still RTFM.

[โ€“] generator@lemmy.zip 1 points 19 hours ago* (last edited 19 hours ago)

Just the case of the packages being removed only a few hours after been published just makes my point of "trusted users" reviewing and reporting then.

And is not only an archlinux/AUR problem, the same happens with python pip, npm, dockerhub, github... With bigger popularity, bigger the target.

These days after the success of Steamdeck many users switched to Linux, and many of those started using arch or based distros like EndeavourOS because some one on reddit, YouTube or other said is the best for new hardware and you can find everything you need on AUR.
New users won't review scripts or PKGBUILD, that's gibberish, just search and install, and a few hours could be too late for some.

I don't care if Linux loses or gains popularity, but if there's no guard rails of some kind of control things could get worse, and even end AUR as it is now.

Having people control what's published or not, probably not the best solution, but leaving it as a wild west also not