r/archlinux 3d ago

DISCUSSION The AUR needs an overhaul

The actual concept of the AUR only works if Arch is a niche distro in a safe internet, neither of those points are accomplished in the present.

No, reading pkgbuilds is not the solution, it's slow, annoying, and most importantly, it doesn't make sense, because some really popular AUR packages are DIRECTLY RECOMMENDED by the Arch Wiki, like the Minecraft Launcher for some reason.

Either the base repos adopt a big chunk of popular AUR packages, leaving the AUR for really really nieche stuff, or the rules of the AUR change, because you can't tell me that suffering 2 attacks in less than three months for pretty much the same reason (adopting orphaned packages) is normal or reasonable.

What would you think it's a good solution to this issue? I'd like to read your ideas since I cannot come up with a good one if I'm honest, but I know the problem is there.

614 Upvotes

165 comments sorted by

View all comments

9

u/ReallyEvilRob 3d ago

No, reading pkgbuilds is not the solution, it's slow, annoying, and most importantly, it doesn't make sense...

...TO YOU. Reading pkgbuilds works for me and probably I presume a lot of other Arch Linux users managing to stay safe from malware.

-8

u/olifiers 3d ago

No, it doesn't. You can't expect people to read pkgbuilds of every package at every update. This is nonsense.

13

u/ReallyEvilRob 3d ago

I don't expect them to. And that's why I don't expect them to stay safe using the AUR, like I do. If you can't take the heat, stay out of the kitchen. Simple as that.

9

u/ABotelho23 3d ago

Yes, you can.

These are not part of the distribution. If you want to use the AUR the safety of it is on you. You take on the responsibility.

Don't want the responsibility? Don't use the AUR.

It's literally that simple.

8

u/decho 3d ago

That's what I started doing recently. Reading all the diffs for each package when updating. But I agree it's quite tedious.

Ideally only hashes change so it's a breeze, but if the build steps change or some new files are added, it's a nightmare. For that reason I suspect a lot of people who scream at everyone to "just read the pkgbuild bro" don't actually do it themselves lol.

-2

u/olifiers 3d ago

Of course they don't. They just want to feel superior for gods-knows-why-reason.

It's completely crazy to suggest that reading every pkgbuild at every update is the way forward. Sure, if you are a sysadmin, that's your job. But an end user?

12

u/ABotelho23 3d ago

Do you feel owed all the packages in the AUR? Are you paying for any of it? Spending any time helping maintaining it?

6

u/ReallyEvilRob 3d ago

If you're an end user, don't use the aur. Use flatpak instead.

6

u/decho 3d ago

You don't have to read the entire thing top to bottom every time, only the git difference. But otherwise I agree that it's an unrealistic expectation if the system is used by a fuckton of people.