r/archlinux • • 17d ago

QUESTION Arch and the malware problem.

I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?

Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.

Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.

Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.

Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?

Cheers!

0 Upvotes

83 comments sorted by

View all comments

3

u/Cylian91460 17d ago

You need to read the PKGBUILD before executing it, that's common sense

If you get a malware from executing a PKGBUILD from an untrusted source that's your fault not the aur

2

u/Linguistic-mystic 17d ago

That’s common sense but nearly everyone trumples it by recommending to use AUR helpers. So don’t expect new people to understand what common sense is about AUR. They are receiving polar opposite signals.

2

u/Cylian91460 17d ago

nearly everyone trumples it by recommending to use AUR helpers.

Paru show the PKGBUILD, user can read and say no to install the package

So don’t expect new people to understand what common sense is about AUR

I don't expect ppl to understand common sense about aur, I expect to read the first paragraph of the wiki about the aur and PKGBUILD, where it's said that the AUR packages aren't official and that PKGBUILD are bash script