Im not programmer but is there a way of making aur packages something more a like reproducable? I mean dont let pkgbuild dowload and install dependencies just check what are installed what are not, and force user to install them manually so we know what are we installing ( like istalling yay for first time). For me ideal situation would be mandatory reproducability of aur packages forced on maintainer...am i insane? If i understand good -bin packages are already compiled so is there any tool i can use to check its 1 to 1 validity with code?
Sent from [Proton Mail](https://proton.me/mail/home) for Android. -------- Original Message -------- On Saturday, 08/08/26 at 21:29 noexec <[email protected]> wrote: > Moving common packages to the extra repos is a good way to reduce AUR > concerns; but it doesn't address the core issues. The AUR concept itself is > sound; and user-focused packages are necessary for a project like this. > However, the AUR lacks a trust system that distinguishes between contributors > with 8 months of history and those with 1 day; and this applies to both > adoptions and new packages. New maintainers should be more scrutinized, not > by their registration date, but when they start maintaining; and dismissing > this by saying "users need to read the PKGBUILD" is irresponsible; especially > when some AUR team members have publicly downplayed the importance of timely > package security updates like browsers and expect users to manually rebuild > every PKGBUILD they depend on outside of official update channels, > demonstrating a troubling disconnect from practical security needs. Creating > new scanners for specific campaigns only perpetuates a cat-and-mouse game. > The signup captcha can be trivially bypassed with a simple script; and > there's no captcha on login, making it easy to mass-login or signup accounts > with rotating proxies and do any action. Simply shutting down the AUR without > fixes won't help. This was tried before with a lazy commit that removed dot > and plus tricks from emails; which wouldn't have fixed the real issues anyway > https://github.com/archlinux/aurweb/commit/1086c17bc8ba925fc2a1807b40fa01dd701da1f6 > Finally; "Antiz" has used his trusted user access to post to personal AUR > packages when the AUR was down. > Note: This message was translated. > On Thursday, August 6th, 2026 at 8:42 AM, doublemiu <[email protected]> > wrote: > >> Hello. I just would like to ask about chances of migrating most popular or >> maintened by developers packages to community repository? Idea we still have >> to upgrade such packages like zen browser, heroic games launcher and many >> others from aur ... >> >> Sent from [Proton Mail](https://proton.me/mail/home) for Android.
