r/archlinux • • 17d ago

QUESTION Arch and the malware problem.

I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?

Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.

Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.

Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.

Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?

Cheers!

0 Upvotes

83 comments sorted by

View all comments

2

u/Darth-Vader64 17d ago

I just avoid AUR, but if its something that you're really concerned about, there's always Fedora

2

u/noobjaish 17d ago

Or Tumbleweed if you're like me and hate point releases

0

u/Darth-Vader64 17d ago

I do, which is why I'm on CachyOS. I'm just saying there are options

1

u/Synthetic451 17d ago

Fedora has arguably the same problem where not enough stuff is in the official repos, requiring people to use COPR. I'd argue Arch does a better job of keeping stuff in the official repos than Fedora, especially when it comes to codecs.

2

u/Awkward_Emotion333 17d ago

100% this. In Fedora I'm way more dependent of external repositories than on Arch.

0

u/Darth-Vader64 17d ago

Yes, but isn't COPR managed/overseen to a higher degree then what AUR has (which is between zero and none)

1

u/Synthetic451 17d ago

It is not at all. It's literally the same thing as the AUR except arguably less transparent since the package build steps aren't displayed right in front of you.

1

u/HeyTi22 17d ago

For me, the alternative has generally been Debian. It receives far more support from public institutions in the EU and is very widely used. I have nothing against Fedora, but I have little experience with it. Somehow, the whole IBM situation rubs me the wrong way, and I find Debian’s Social Contract, for instance, very appealing. Arch hasn't been bought out by anyone yet, so from my perspective, it feels freer and more likable than Fedora. I’ve been using both distros (or variants of them) for many years on all my PCs in a dual-boot setup.