Or maybe don’t use AUR blindly? You’re doing the equivalent of sudo curl --- | bash. Who knows what the script is doing. So only do it if you truly trust it. That’s why we have warnings plastered all over. That’s also why a warning label and sticker exists. And this is precisely the reason easy no user input AUR helpers are greatly discouraged
You said it yourself that it is a community repository. No difference between that and the internet forum. You are putting the burden of accountability on the maintainer that way. Which I would remind you, is unpaid unlike say, github and npm that HAS a financial means to do a lot of security implementation. Yet those platforms still fail to do it.
Also, humans ARE the first layer of defense. Because anything you do on your device (on linux anyway, and specifically arch) is YOUR decision. Antivirus and everything else should kick in when the human fails.
You are normalizing people downloading things off the unvetted internet like on windows. Linux has a vetted repo already. THOSE are what people should be using and I’m fine with if those are being blamed. Everything else is USER due diligence. That is why the existence of easily installing malware like limewire does not justify blaming the platform. Or do you also blame torrenting site when they are chock full of malware?
Sure, your proposed solution is a good way to weed out the low hanging fruit. But I don’t like that it may create friction for normal users. AUR was never meant to be a FOSS project on its own with a full time maintainer that maintains PKGBUILD and the infra.
Like I said before, it is more akin to an internet forum and pastebin more than a full fledged package repository. And to be fair, it isn’t a package repo anyway. It’s like a cmake / makefile sharing site. Building and packaging for arch is just that easy compared to say, debian.
If people want to use a repo, there is chaotic aur. Maybe that could be the way too. A dedicated community project to vet the AUR. Or the project maintainer itself could provide a pkgbuild directly on their repo.
Just don’t ever blame the maintainer for providing a place to store something for free and open to anyone. Especially if it is your choice to get something from said place and be surprised that it is malware.
Maybe maintenance of packages shouldn’t just be handed over to newly created accounts. This is a design flaw on AUR’s part.
That is the whole purpose of AUR, users can create and share packages with minimum fuss. That does not mean that it is a good idea to run the code of some random guy on your computer.
But open source has always worked like that, by code sharing and collaboration - on tapes, on FTP servers, on Sourceforge or github and today on codeberg. The way the Arch User Repository (this is AUR spelled out) makes this easy is great!
Just don’t run random code that you don’t understand, and cannot reasonably trust.
Without the AUR Arch becomes a third world country distro because the official repos have only the basics.
Arch has 17,000 packages and is one of the largest distros. If you want more, you can use Debian, or perhaps Ubuntu if you really need non-free drivers and codecs, (or maybe NixOS, which has a fuckton of packages, but you won’t get the same quality).
deleted by creator
“No way to prevent this” says only repository where this regularly happens
deleted by creator
Or maybe don’t use AUR blindly? You’re doing the equivalent of
sudo curl --- | bash. Who knows what the script is doing. So only do it if you truly trust it. That’s why we have warnings plastered all over. That’s also why a warning label and sticker exists. And this is precisely the reason easy no user input AUR helpers are greatly discourageddeleted by creator
You said it yourself that it is a community repository. No difference between that and the internet forum. You are putting the burden of accountability on the maintainer that way. Which I would remind you, is unpaid unlike say, github and npm that HAS a financial means to do a lot of security implementation. Yet those platforms still fail to do it.
Also, humans ARE the first layer of defense. Because anything you do on your device (on linux anyway, and specifically arch) is YOUR decision. Antivirus and everything else should kick in when the human fails.
You are normalizing people downloading things off the unvetted internet like on windows. Linux has a vetted repo already. THOSE are what people should be using and I’m fine with if those are being blamed. Everything else is USER due diligence. That is why the existence of easily installing malware like limewire does not justify blaming the platform. Or do you also blame torrenting site when they are chock full of malware?
deleted by creator
Sure, your proposed solution is a good way to weed out the low hanging fruit. But I don’t like that it may create friction for normal users. AUR was never meant to be a FOSS project on its own with a full time maintainer that maintains PKGBUILD and the infra.
Like I said before, it is more akin to an internet forum and pastebin more than a full fledged package repository. And to be fair, it isn’t a package repo anyway. It’s like a cmake / makefile sharing site. Building and packaging for arch is just that easy compared to say, debian.
If people want to use a repo, there is chaotic aur. Maybe that could be the way too. A dedicated community project to vet the AUR. Or the project maintainer itself could provide a pkgbuild directly on their repo.
Just don’t ever blame the maintainer for providing a place to store something for free and open to anyone. Especially if it is your choice to get something from said place and be surprised that it is malware.
That is the whole purpose of AUR, users can create and share packages with minimum fuss. That does not mean that it is a good idea to run the code of some random guy on your computer.
But open source has always worked like that, by code sharing and collaboration - on tapes, on FTP servers, on Sourceforge or github and today on codeberg. The way the Arch User Repository (this is AUR spelled out) makes this easy is great!
Just don’t run random code that you don’t understand, and cannot reasonably trust.
deleted by creator
The Arch team is not responsible for this code.
And to add, demanding to do more work from volunteers which already do a lot of work for free is rude. If you want something done - do it yourself.
deleted by creator
Not from AUR.
deleted by creator
Arch has 17,000 packages and is one of the largest distros. If you want more, you can use Debian, or perhaps Ubuntu if you really need non-free drivers and codecs, (or maybe NixOS, which has a fuckton of packages, but you won’t get the same quality).
And what do you need so many packages for?
deleted by creator