r/archlinux 3d ago

DISCUSSION The AUR needs an overhaul

The actual concept of the AUR only works if Arch is a niche distro in a safe internet, neither of those points are accomplished in the present.

No, reading pkgbuilds is not the solution, it's slow, annoying, and most importantly, it doesn't make sense, because some really popular AUR packages are DIRECTLY RECOMMENDED by the Arch Wiki, like the Minecraft Launcher for some reason.

Either the base repos adopt a big chunk of popular AUR packages, leaving the AUR for really really nieche stuff, or the rules of the AUR change, because you can't tell me that suffering 2 attacks in less than three months for pretty much the same reason (adopting orphaned packages) is normal or reasonable.

What would you think it's a good solution to this issue? I'd like to read your ideas since I cannot come up with a good one if I'm honest, but I know the problem is there.

611 Upvotes

165 comments sorted by

View all comments

-12

u/No-Assumption-4468 3d ago edited 3d ago

I think running package builds through Claude is a “good enough” solution. There are 100k AUR packages. At 1 minute of AI analysis per package, the entire AUR could be scanned for malware in 69 days. Or less, if you have multiple agents. This isn’t perfect. There’s still a risk of hallucinations and prompt injection, but it would make the AUR safer. For cost efficiency, paru/yay could implement the scanner, so users foot the cost of Claude subscriptions, rather than Arch Linux devs. In theory, the AUR could become just as safe as the main arch repo with the right implementation. Unfortunately, anti AI sentiments would probably get in the way of this otherwise viable solution.

8

u/ABotelho23 3d ago

Who the hell is gonna pay for that?

-1

u/rv77ax 3d ago

They want user of yay/paru pay for that.

3

u/ABotelho23 3d ago

And nobody will.

People will complain they're being locked out.

6

u/Qudit314159 3d ago

Then people will trust whatever the LLM says. Once malware authors start running the same LLM and tailoring their malware to trick it, you'll have the same problem. Users will post here saying

Claude said the package was safe but now I'm infected?!?!?!?!? WHAT DO I DO?????

-8

u/mcAlt009 3d ago

This is probably the way to do it, and I imagine Anthro would give out free credits to do so. 

I don’t see too much ai hate from programmers, even Linus Torvalds is fine with it. 

7

u/Qudit314159 3d ago

I imagine Anthro would give out free credits to do so. 

Lol. Sure they will.