• Lucy :3@feddit.org
    link
    fedilink
    arrow-up
    13
    ·
    10 hours ago

    The most unsafe factor of the AUR is aur helpers and their goal to dumb everything down and streamline the process as if the AUR where an official repo

    • CubitOom@infosec.pub
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 hours ago

      I’m not entirely sure I agree, I think the issue is with default settings.

      Like you could use both yay and paru to diff the PKGBUILD of the most recent updat and then read it, and then approve each. And I think that’s pretty helpful. But you could also just blindly accept the update with the right config or flag and that is not a good practice.