|
|
|
|
|
by OJFord
2 hours ago
|
|
AUR packages consist of packaging a third-party software (whether binary or source built as part of the package) for use on Arch. Most updates are just bumping the upstream software version and its checksum, as GP describes, and yes arguably you should be reviewing the change to that software too, but that's a separate threat. And it may be a proprietary binary, in which case on update you've already decided to trust the third-party, so the diff shows you that nothing has changed in that regard, the trusted party simply released a new opaque version. |
|