Remix.run Logo
morserer 5 hours ago

Iirc it was to force the extra step necessary for the user to acknowledge that the AUR can bootstrap malware if used blindly.

This seems to be a relatively consistent discussion surrounding AUR helper development; for example, adding UX to incentivise users to read PKGBUILDs, lest the AUR becomes an attractive vector for skids.

No one wants the AUR to become NPM, and the thing that will incentivise that is uneducated users. Having the small barrier of not having helpers in the main repos is an effective way of accomplishing that.