|
|
|
|
|
by dwedge
2 hours ago
|
|
Call me naive (I don't use arch) but if that's the only change then what's the point releasing the change? Unless pkgver refers to an external dependency or a binary, in which case you might as well say reading the changelog counts as reading the code |
|
You're right, I don't audit every line of code in new versions of Firefox/Chrome/etc. I chose to trust the download URL when I first installed that package. Then on updates, I can check at a glance that the script hasn't changed to point to another URL or in other suspicious ways.
There are two possible threats here: "random AUR user" and "Google". I'm protected from the former deciding to bundle malware, but not the latter.