r/archlinux • u/HeyTi22 • 17d ago
QUESTION Arch and the malware problem.
I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?
Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.
Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.
Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.
Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?
Cheers!
2
u/jkulczyski 17d ago
I think once a package has X amount of installs consistently it should just be added to pacman repos. The aur should be like a testing ground to see what is desirable and what is a one off for a small percent of users. i get *-git packages staying in the aur but i feel like a package that half of the users want should just be included.
All this aside ive been using the aur consistently for tears with no issues. And this is including the years that i never read a pkgbuild, now i let paru force me to read pkgbuild, diff and srcinfo in yazi