Im not programmer but is there a way of making aur packages something more a 
like reproducable? I mean dont let pkgbuild dowload and install dependencies 
just check what are installed what are not, and force user to install them 
manually so we know what are we installing ( like istalling yay for first 
time). For me ideal situation would be mandatory reproducability of aur 
packages forced on maintainer...am i insane? If i understand good -bin packages 
are already compiled so is there any tool i can use to check its 1 to 1 
validity with code?

Sent from [Proton Mail](https://proton.me/mail/home) for Android.

-------- Original Message --------
On Saturday, 08/08/26 at 21:29 noexec <[email protected]> wrote:

> Moving common packages to the extra repos is a good way to reduce AUR 
> concerns; but it doesn't address the core issues. The AUR concept itself is 
> sound; and user-focused packages are necessary for a project like this. 
> However, the AUR lacks a trust system that distinguishes between contributors 
> with 8 months of history and those with 1 day; and this applies to both 
> adoptions and new packages. New maintainers should be more scrutinized, not 
> by their registration date, but when they start maintaining; and dismissing 
> this by saying "users need to read the PKGBUILD" is irresponsible; especially 
> when some AUR team members have publicly downplayed the importance of timely 
> package security updates like browsers and expect users to manually rebuild 
> every PKGBUILD they depend on outside of official update channels, 
> demonstrating a troubling disconnect from practical security needs. Creating 
> new scanners for specific campaigns only perpetuates a cat-and-mouse game. 
> The signup captcha can be trivially bypassed with a simple script; and 
> there's no captcha on login, making it easy to mass-login or signup accounts 
> with rotating proxies and do any action. Simply shutting down the AUR without 
> fixes won't help. This was tried before with a lazy commit that removed dot 
> and plus tricks from emails; which wouldn't have fixed the real issues anyway 
> https://github.com/archlinux/aurweb/commit/1086c17bc8ba925fc2a1807b40fa01dd701da1f6
>  Finally; "Antiz" has used his trusted user access to post to personal AUR 
> packages when the AUR was down.
> Note: This message was translated.
> On Thursday, August 6th, 2026 at 8:42 AM, doublemiu <[email protected]> 
> wrote:
>
>> Hello. I just would like to ask about chances of migrating most popular or 
>> maintened by developers packages to community repository? Idea we still have 
>> to upgrade such packages like zen browser, heroic games launcher and many 
>> others from aur ...
>>
>> Sent from [Proton Mail](https://proton.me/mail/home) for Android.

Reply via email to