| ▲ | embedding-shape 2 hours ago | ||||||||||||||||
I can tell you misunderstand what the AUR actually is. It's not a package registry maintained by anyone, and it's also not limited to "build from source" or whatever. It's more like npm if anything, if you're familiar with that distribution mechanism. | |||||||||||||||||
| ▲ | matheusmoreira an hour ago | parent | next [-] | ||||||||||||||||
> It's more like npm if anything, if you're familiar with that distribution mechanism. True, but I'd reverse the order. It's npm, pip, cargo, gem and all the others that are like the AUR. They're every bit as dangerous as the AUR, yet the AUR is the only one that singles itself out by warning people of the danger. Anyone can sign up and push packages. I've literally done that myself, even though nobody in the Arch Linux community knows or trusts me. AUR is the only one where users are repeatedly made aware of this danger. All the others normalize and encourage importing random unvetted dependencies for the sake of developer convenience. | |||||||||||||||||
| |||||||||||||||||
| ▲ | dwedge 2 hours ago | parent | prev [-] | ||||||||||||||||
I misunderstood your comment more and in that case I apologise. I thought you meant you review all packages you install or upgrade from any source. In my case I'm guilty of not checking brew updates (even from casks) on Mac, but I'm also guilty of only updating them every couple of months so it probably balances out. | |||||||||||||||||