On Sat Aug 8, 2026 at 11:53 AM PDT, noexec wrote:
> However, the AUR lacks a trust system that distinguishes between contributors
> with 8 months of history and those with 1 day; and this applies to both

I brought this up a month or so ago; at the time, I was trying to use an 
existing
facility for it (validpgpkeys and finding core Arch maintainers willing to sign 
my
key), which was a dead end.

I still believe in a web-of-trust model with the folks Arch users already
explicitly trust (the Arch maintainers) at the center. It wouldn't necessarily
prevent people from installing untrusted packages, but it would allow for any
number of QoL improvements that would strictly improve upon the current security
model.

I've found no facility within the current tooling that a maintainer like myself
can use to improve trust in AUR packages. I've also seen no email saying "we
don't know how to fix this, please help," so aside from exploring what options
are available (a dead end) pending an official approach, I'm just waiting to see
what the Arch team comes up with.

--- SER   
Sean E. Russell (https://ser1.net)    
OpMsg: https://ser1.net/.well-known/opmsg.txt    
GPG key: https://ser1.net/.well-known/pgp.asc    
Minisign: https://ser1.net/.well-known/minisign.pub    
Age: age195vpft7nzsy83medxagqqsge0lrcuf9txe3z2znlu2wsk69cdu4sx8nfvp    

Reply via email to