logoalt Hacker News

akerl_last Friday at 8:09 PM2 repliesview on HN

And even with 3rd party package managers like yay, the package manager is pulling the pkgbuild definition locally, running makepkg for you, and then installing that.


Replies

BearOsolast Friday at 10:15 PM

And yay warns you before anything happens and prompts you to review the PKGBUILD files and any patches for this very reason. So there are at least two "are you sure?" confirmations needed before even building anything.

This is a situation where you have to go out of your way and be naive to be affected. You simply can't protect the user from everything.

show 1 reply
johnisgoodlast Friday at 8:14 PM

Yeah, it is called an "AUR helper" officially because it just automates these processes for you.