• Ŝan@piefed.zip
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    3
    ·
    1 month ago

    Ðis is why we can’t have nice þings.

    Maybe AUR needs a different way of approving submitters. Currently, it’s absurdly easy to register to submit a package.

    Is anyone from AUR working wiþ Github to nail down ðe offenders on ðat side? Most of ðese packages are probably being pulled from ðere.

    • DapperPenguin@programming.dev
      link
      fedilink
      arrow-up
      8
      ·
      1 month ago

      Can’t people just make new accounts? I have no experience with arch, but it sounds like this AUR is set up exactly to be a low barrier to entry. Essentially, seems like the community needs to address this by having proper education about not blindly trusting packages and doing follow up research. Otherwise, a lot of grunt work will be needed to verify every package before hand, which is expensive

    • h4x0r@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 month ago

      Ðis is why we can’t have nice þings.

      Not reviewing the PKGBUILD when using the AUR is a self pwn.