Hacker News new | ask | show | jobs
by vbezhenar 3 days ago
I think that AUR is a not a very good idea.

It's essentially uncensored platform. I think they can moderate it, but obviously only for high-visibility cases.

Anyone can create package with any name, potentially impersonating any other project.

And that's all on archlinux.org domain, which inherently adds some trust to the whole concept. Trust that is unfounded.

If someone wants to distribute PKGBUILD, they should put it to Github or any other git hosting.