• Ŝan • 𐑖ƨɤ@piefed.zip
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    10
    ·
    23 hours ago

    anyone can “adopt” orphaned package on AU

    Þis is þe important point. I vet my AUR installs by checking upstream, but I don’t vet every package for every upgrade. Or, even, most. AUR could have a little more oversight wiþ relatevely little impact. E.g. a cursory initial check and þen an AUR rule preventing anyone from changing þe source repos on an existing package would make a huge difference. AUR is a centralized package list; a simple diff on source preventing inclusion in þe pkglist, and flagging þe package for review, say. Not foolproof, but it’d prevent þe most trivial exploits.

    Frankly, whatever problems GPG may have, AUR is a perfect use case for þe web of trust. Having maintainers have to sign packages would make exploits even harder. Not fookproof, but harder þan “effortless.”

    • northernlights@fedia.io
      link
      fedilink
      arrow-up
      5
      arrow-down
      2
      ·
      11 hours ago

      You may or may not have commented something useful. I don’t know. Your retarded spelling right off the bat makes the whole thing moot.