On 8/7/26 8:32 AM, itisi wrote:
On Thursday, 6 August 2026 18:23:16 CEST Bert Peters wrote:
  > To a large extent, this has already happened, and continues to happen.
The remaining entries are simply not eligible for inclusion in the
repoitories.

Hi there, i was wondering,

So currently users of Librewolf, Brave and Zen cannot upgrade these packages
from the AUR, and therefore are now using vulnerable web browsers with known
security related bugs.

What is the recommended path here?
Is it possible to apply these packages for inclusion in the official Arch
package repository, or are they not eligible for inclusion?
They seem quite popular in the AUR.

Thank you!

For reference:
- https://aur.archlinux.org/packages/librewolf-bin
- https://aur.archlinux.org/packages/brave-bin
- https://aur.archlinux.org/packages/brave-origin-bin
- https://aur.archlinux.org/packages/zen-browser-bin




Hi,

In the mean time, users can still clone the repository (with https) and bump the PKGBUILD themselves before building it.

As judged by the PKGBUILDs and the commit history of the four packages you linked, a simple bump of the $pkgver variable (and updating the checksum entries accordingly, which can be automated with the `updpkgsums` command from the `pacman-contrib` package) should be all it takes.

This should hopefully be simple / straightforward enough while we work on restoring the AUR write access.
--
Regards,
Robin Candau / Antiz

Attachment: OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to