Moving common packages to the extra repos is a good way to reduce AUR concerns; 
but it doesn't address the core issues. The AUR concept itself is sound; and 
user-focused packages are necessary for a project like this. However, the AUR 
lacks a trust system that distinguishes between contributors with 8 months of 
history and those with 1 day; and this applies to both adoptions and new 
packages. New maintainers should be more scrutinized, not by their registration 
date, but when they start maintaining; and dismissing this by saying "users 
need to read the PKGBUILD" is irresponsible; especially when some AUR team 
members have publicly downplayed the importance of timely package security 
updates like browsers and expect users to manually rebuild every PKGBUILD they 
depend on outside of official update channels, demonstrating a troubling 
disconnect from practical security needs. Creating new scanners for specific 
campaigns only perpetuates a cat-and-mouse game. The signup captcha can be 
trivially bypassed with a simple script; and there's no captcha on login, 
making it easy to mass-login or signup accounts with rotating proxies and do 
any action. Simply shutting down the AUR without fixes won't help. This was 
tried before with a lazy commit that removed dot and plus tricks from emails; 
which wouldn't have fixed the real issues anyway 
https://github.com/archlinux/aurweb/commit/1086c17bc8ba925fc2a1807b40fa01dd701da1f6
 Finally; "Antiz" has used his trusted user access to post to personal AUR 
packages when the AUR was down.
Note: This message was translated.
On Thursday, August 6th, 2026 at 8:42 AM, doublemiu <[email protected]> wrote:

> Hello. I just would like to ask about chances of migrating most popular or 
> maintened by developers packages to community repository? Idea we still have 
> to upgrade such packages like zen browser, heroic games launcher and many 
> others from aur ...
>
> Sent from [Proton Mail](https://proton.me/mail/home) for Android.

Reply via email to