| ▲ | dwedge 2 hours ago | |||||||||||||||||||||||||||||||
> No, I'm sorry but who on earth installs random software from random strangers Everyone. People who don't tend to build from source and the convenience of package managers has outweighed this for most people for years now. Even if you review the code do you review every library it pulls in? Because I have to tell you I don't believe you, and if most people did do that then these supply chain attacks would be minor news. | ||||||||||||||||||||||||||||||||
| ▲ | embedding-shape 2 hours ago | parent [-] | |||||||||||||||||||||||||||||||
I can tell you misunderstand what the AUR actually is. It's not a package registry maintained by anyone, and it's also not limited to "build from source" or whatever. It's more like npm if anything, if you're familiar with that distribution mechanism. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||