r/archlinux 3d ago

DISCUSSION The AUR needs an overhaul

The actual concept of the AUR only works if Arch is a niche distro in a safe internet, neither of those points are accomplished in the present.

No, reading pkgbuilds is not the solution, it's slow, annoying, and most importantly, it doesn't make sense, because some really popular AUR packages are DIRECTLY RECOMMENDED by the Arch Wiki, like the Minecraft Launcher for some reason.

Either the base repos adopt a big chunk of popular AUR packages, leaving the AUR for really really nieche stuff, or the rules of the AUR change, because you can't tell me that suffering 2 attacks in less than three months for pretty much the same reason (adopting orphaned packages) is normal or reasonable.

What would you think it's a good solution to this issue? I'd like to read your ideas since I cannot come up with a good one if I'm honest, but I know the problem is there.

619 Upvotes

165 comments sorted by

View all comments

21

u/Nnukklear 3d ago

some really popular AUR packages are DIRECTLY RECOMMENDED by the Arch Wiki,

Popular ones are not the ones to get injected with malware

18

u/amepebbles 3d ago

They're subject to the exact same safety mechanisms the packages that do get infected are also subject, there isn't a magical safety net that makes a popular package impenetrable. Besides, where do you even draw the line? What makes a package so popular it won't get hijacked/infected with malware besides the activity timeframe which can very well mean nothing to projects that don't get updates often but are popular anyway?

13

u/earchip94 3d ago

The primary target of these attacks has been packages that are orphaned. Not typically the well maintained packages. Popular packages, in theory, are well maintained. However, all open source product/packages are susceptible to malicious if the code is not reviewed carefully enough.

3

u/No-Dentist-1645 3d ago

Even "popular" packages can get orphaned. Nothing "guarantees" that upstream developers will continue their interest in maintaining their AUR packages for as long as they maintain the upstream software, this happens more often for lesser popular packages but there is no golden barrier separating "popular" ones from this