Hi Sam,
In the latter case, it's still unclear to me what's wrong with `revert` rather than `reset --hard`, as it would still fix the tip of the tree.
It’s true that this would still fix the tip of the tree.
However, the AUR would be permanently hosting malicious code if the commits were merely reverted. This opens up a whole bunch of other issues. For example, one single person in bad faith would be able to cause corporate proxies and search engines all over the place to blocklist the entire domain by merely reporting the cgit URL pointing to the malicious revision. Not to mention the legal ramifications.
I’m not aware of any legitimate platform that keeps malicious or compromised software versions around. They all remove these asap, likely for similar reasons.
Regards Claudia
OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
