• Ricaz@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    28
    ·
    4 days ago

    It’s a USER repository, where you literally download install files from unverified strangers.

    There’s a reason all the AUR helpers prompt you to verify all the files before they will build or install anything.

    • fruitcantfly@programming.dev
      link
      fedilink
      arrow-up
      12
      ·
      4 days ago

      I wonder percentage of Arch users are actually capable of verifying that an AUR package is safe to install. I doubt that the number is very high, especially with the growing popularity of the distro

      • Ricaz@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        5
        ·
        3 days ago

        These days it’s very small. Most people just wanna use Arch because it’s cool.

        While I do wholeheartedly think it’s by far the best distro, I also frequently recommend Mint for newbies if they don’t enjoy learning on their own.

        • kieron115@startrek.website
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 days ago

          In my case you can unironically blame Valve. I wanted an Arch-based distro to stay as close to SteamOS as possible but I have an nvidia GPU for the foreseeable future (unless I win the lottery or something).

    • brucethemoose@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      3 days ago

      It’s still hosted on archlinux.org.

      However “YMMV” the scripts are intended to be, they can’t host throngs of malware on their domain.

      …Well, I guess they could if they want to become the next npm, but it still seems like a legal liability.

      I’m not saying it should be taken down, but the status quo is definitely no longer acceptable.