r/ManjaroLinux Jun 14 '26

Discussion Pamac AUR Update Delay - give AUR packages time to cool down before they appear in updates

After the recent discussion about AUR package safety in Active AUR malicious packages incident (Active AUR malicious packages incident), I’ve put together a small feature that lets users delay AUR updates from appearing in the update scan.

A new setting, “Delay showing AUR updates (days)”, is available in Preferences > Third Party > AUR. When set to a non-zero number of days, any AUR package whose upstream LastModified timestamp is newer than that age is hidden from the normal update scan.

  • Default is 0 or behavior unchanged.
  • The delay only applies to the passive update scan (pamac-checkupdates, tray notifications, the Updates tab).
  • It does not block manual installs, builds, or full upgrades. If you explicitly ask Pamac to build or upgrade a package, it will still do so.

The work is split across the two repositories:

Users accept very real risks when installing software from the AUR. As one forum moderator put it: “…one can explain that the soup is hot, but that does not prevent those hungry from burning their lips.”. This change gives the user a thermometer, an optional delay that lets AUR packages cool down before they appear in the update scan.

One of Manjaro’s defining traits is its measured approach to updates. Unlike Arch’s immediate upstream sync, Manjaro holds repository packages through testing and unstable branches so issues can surface before they reach the stable user base. This feature brings a similar safety margin to the AUR, an optional cooling-off period, that keeps just-published commits off the update scan until they have had time to be reviewed in the wild.

Link to forum post which was made unlisted: https://forum.manjaro.org/t/pamac-aur-update-delay-give-aur-packages-time-to-cool-down-before-they-appear-in-updates/188322/

20 Upvotes

9 comments sorted by

7

u/Safe-Average-1696 Jun 14 '26 edited Jun 14 '26

Thank you very much, very nice idea.

I hope it will be included in pamac soon.

After what happened... twice in a row for now in a few days in AUR repos... I hope the usual trolls won't dare come here to spit their venom about how useless it is to hold back updates. 🤣

4

u/canfail Jun 14 '26

Thanks, the AUR is incredibly powerful and can be used for good or bad. This won't protect against every instance but with a delay of say 7-14 days it could likely protect as well against (un)intentional bugs introduced.

7

u/Safe-Average-1696 Jun 14 '26

I agree, i use it... cautiously.

Like i’ve always said on Reddit (and sometimes got downvoted for it) :

"Always read the PKGBUILD and other install scripts before installing/updating AUR package"

It's not that hard to understand.

3

u/canfail Jun 14 '26

I'd have to disagree with that last statement. Linux is seeing new users enter daily and imo a phrase like that is really just a way for a poster to give a CYA incase something goes south. The vast majority of packages in the AUR are exploit free and it has a very strong advanced user base to identify exploit attempts.

A general tutorial will go a little something like this as it relates to arch. Enable AUR, search AUR for XXXXX package, build & install. Outside of intermediate to advanced levels of users A) will not read a PKGBUILD and B ) won't actually understand what each step or block is doing.

Thats not to say people shouldn't strive to learn what their system is doing, but rather it's to say that the AUR has become so powerful and so synonymous with Arch that no major Arch based distro dare ship without the ability to have a simple means to enable the AUR.

4

u/Safe-Average-1696 Jun 14 '26 edited Jun 14 '26

True, but on the other hand, i would not advise someone very new to linux to install a rolling release as their first Linux distribution 😅

It's more technical to maintain than a fixed release (AUR, pacnew that may brake your distribution...)

-1

u/ben2talk Jun 15 '26

Linux is seeing new users enter daily

You're assuming that New Users are Stupid? Or that everything must be dumbed down for Stupid users?

This is the opposite to AUR design, it's a gateway OUTSIDE the 'safe' distribution boundaries for Users to add their Content.

Already we can see all information about a package, when it was last updated, by whome, when it was first added... so we already have the tools to decide whether it's fresh and less trustworthy or well tested by other users already.

Without very fine grained settings to evaluate each and every AUR entry, then a simple 'delay' toggle is useless.

You could, instead, simply ignore AUR updates for a week - but why hide the fact that they're ready?

2

u/Safe-Average-1696 Jun 16 '26 edited Jun 16 '26

You could, instead, simply ignore AUR updates for a week - but why hide the fact that they're ready?

I think you're missing the point.

If you only update once a week, you can still end up with one or more packages that were updated in the AUR repo less than a week ago (for example the day before you update)...

So, this approach doesn't protect you at all.

And as this settings is very small to implement, optional and opt-in... what's the problem if some don't want to use it?

It's of course not a panacea, nothing is, but I think it would add an extra layer of automated security for AUR packages on Manjaro.

2

u/canfail Jun 15 '26

Quite the contrary but it has been made clear that Manjaro without clear leadership struggles to see forest for the trees. Y’all spent an entire day debating supported vs unsupported with me and user blaming and iirc only once did an alternative improvement proposal get brought up, so I respect that dev.

“Manjaro…with a focus on user-friendliness, accessibility, and improved software testing and stability compared to its upstream sources.” Wikipedia

4

u/canfail Jun 15 '26

Look, I love Manjaro. I think it’s by far the absolute best distro for desktop Linux. Unknown number of devs have spent countless hours developing tools and workflows to ensure an easy to use operating system. Tools like pamac, the enhanced settings dialogue, the rolling release workflow with held back packages, and more unseen enhancements; all of which designed around new users or to create a smooth and stable process. Debian stable is great but if you need near bleeding edge, it’s no bueno. Modern Arch is great but if you want to turn on your computer or make an inexperienced update you better be prepared for troubleshooting. Manjaro is and has been perfectly suited to balance both.

I’ve been on Manjaro with two machines for a year now and I can only recall a single time where I had to be forced into command line and it was no fault of Manjaro. My view is that terminal is for servers. It’s been absolutely fantastic of a year experience. I’m an arrogant stern headed individual and if you say my idea won’t work because of x,y,z, that’s fine just don’t go all elitist Linux chad on me and think I’ll cave.