• fruitcantfly@programming.dev
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    2 days ago

    AUR is not unique in being a user repository, but it seems somewhat unique in having basically zero oversight. Which is a bad idea for reasons that should be painfully obvious by now.

    For comparison, Gentoo’s GURU repository allows everyone to submit packages, but limits the ability to accept these submissions to a subset of trusted users

    • BB_C@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      All community projects are open contribution. Most non-community ones too. You know, almost the whole point of open-source!

      But that’s not the same as “user repo”, which is a wild west concept on purpose.

    • kieron115@startrek.website
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      2 days ago

      GURU bills itself as an official repository that’s user-maintained. AUR makes no claims of being official as far as I can see from their website.

        • BB_C@programming.dev
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          2 days ago

          It’s officially centrally hosting the non-pre-moderated non-official user contributed build-scripts, where “user” means literally anyone.

          I’m not sure what argument you’re trying to “win”, and to what end. Or why do you think anyone would care about the manufactured confusion you’re trying to concoct.

          • fruitcantfly@programming.dev
            link
            fedilink
            arrow-up
            2
            ·
            2 days ago

            Which is not much different from the disclaimer about GURU, though GURU does a much better job at explaining the risks involved in using it:

            Disclaimer

            Please note that the GURU project is maintained and reviewed entirely by Gentoo users. It is only subject to minimal supervision from individual Gentoo developers, and is not supported by projects such as Gentoo Security. While our Trusted Contributors do their best to keep GURU safe, it is possible for it to contain vulnerable, badly broken or even malicious software. You are using it on your own responsibility.