|
|
|
|
|
by Foxboron
8 days ago
|
|
> Expecting users to manually review every single change, for every single AUR package they are using, every single time they do an update or installation is just unreasonable if you want to AUR to be useful at all for the general user. How many AUR packages are you assuming people are installing? |
|
I'm assuming people are using the AUR to install programs that are sufficiently complex and the idea one can trivially audit a complex program and all of its dependencies is foolish. The foolishness of that expectation scales with the number of complex programs installed.
The idea that users should "just check the source code every single time" has never been, nor will it ever be, a reasonable solution to supply chain attacks.