logoalt Hacker News

rvzyesterday at 11:41 PM8 repliesview on HN

Who still uses Arch btw after this?


Replies

rcxdudetoday at 12:14 AM

The AUR has consistently had warnings around it of 'verify the PKGBUILD', far more so than any other package repository that allows anyone to sign up. Probably the only notable difference is the ease of taking over an orphaned package.

zbentleytoday at 1:11 AM

The AUR is not the Arch package manager or repository. The main Arch package repos are managed similarly to Debian, or Fedora, or whatever--caveat Arch's nature as a rolling release, but in terms of vetting and ownership/security, the approaches are similar. pacman installs from regular, real, vetted repositories by default. pacman will never install from the AUR. pacman is the official Arch package manager and the only one that is provided with the main Arch distribution/install instructions.

The AUR is, as many others have pointed out, a deliberately un-vetted pile of random Git repos. Arch deliberately doesn't even ship with a default one-click installer for AUR packages; their published guidance is "git clone this stuff from wherever it's hosted and build it at your own risk". Plenty of third-party, non-Arch-blessed tools turn that into a one-click process, but it's not "part" of Arch itself--at least not any more than, like, curl | bash or directions on how to add rando websites to /etc/apt/sources.list.d is part of Debian and friends.

I've used Arch as a daily driver for years. At peak, I've had five (5) total packages, with no transitives, installed from the AUR. Today I have one: sublime-text-4. It's perfectly possible--and extremely reasonable for many users, even power users--to live in an AUR-less world, or to use so few AUR packages that the guidance of "read what you're installing, doofus" is manageable and not onerous.

anagram666yesterday at 11:53 PM

If you want something from the AUR, just don't be lazy, read the pkgbuild.

QuaternionsBhoptoday at 1:32 AM

I was not affected

beej71today at 2:08 AM

I do. I just keep reading the diffs on the PLGBUILDs.

segfalt_yesterday at 11:55 PM

I do, I'm just choosy about aur packages I use

giancarlostoroyesterday at 11:44 PM

I still do, I just don't touch AURs anymore.

akerl_yesterday at 11:43 PM

Is there another distro that has an equivalent of the AUR with handling you think is preferable?

show 3 replies