• Ricaz@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    28
    ·
    13 天前

    It’s a USER repository, where you literally download install files from unverified strangers.

    There’s a reason all the AUR helpers prompt you to verify all the files before they will build or install anything.

    • fruitcantfly@programming.dev
      link
      fedilink
      arrow-up
      12
      ·
      13 天前

      I wonder percentage of Arch users are actually capable of verifying that an AUR package is safe to install. I doubt that the number is very high, especially with the growing popularity of the distro

    • brucethemoose@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      12 天前

      It’s still hosted on archlinux.org.

      However “YMMV” the scripts are intended to be, they can’t host throngs of malware on their domain.

      …Well, I guess they could if they want to become the next npm, but it still seems like a legal liability.

      I’m not saying it should be taken down, but the status quo is definitely no longer acceptable.