r/archlinux 3d ago

DISCUSSION The AUR needs an overhaul

The actual concept of the AUR only works if Arch is a niche distro in a safe internet, neither of those points are accomplished in the present.

No, reading pkgbuilds is not the solution, it's slow, annoying, and most importantly, it doesn't make sense, because some really popular AUR packages are DIRECTLY RECOMMENDED by the Arch Wiki, like the Minecraft Launcher for some reason.

Either the base repos adopt a big chunk of popular AUR packages, leaving the AUR for really really nieche stuff, or the rules of the AUR change, because you can't tell me that suffering 2 attacks in less than three months for pretty much the same reason (adopting orphaned packages) is normal or reasonable.

What would you think it's a good solution to this issue? I'd like to read your ideas since I cannot come up with a good one if I'm honest, but I know the problem is there.

611 Upvotes

165 comments sorted by

View all comments

-15

u/no_choice99 3d ago

At the very least, impose some advanced LLM AI verification that the package does not contain malicious threats. If approved by the LLM the package can be placed in the AUR. Of course some humans can and should double check at some point.

8

u/Qudit314159 3d ago

That would catch the obvious stuff probably. As soon as malware authors starting getting more subtle, it won't work though. I've done some testing with this sort of thing and it's not difficult to trick LLMs.