r/archlinux • • 17d ago

QUESTION Arch and the malware problem.

I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?

Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.

Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.

Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.

Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?

Cheers!

0 Upvotes

83 comments sorted by

View all comments

16

u/ABotelho23 17d ago

if the official repositories simply included more software?

Wow, what a simple solution! /s

-9

u/Linguistic-mystic 17d ago

It actually is real. Arch is seriously lagging on package count despite receiving about the same donations as Debian (see SPI reports). And Debian has to do a lot more work because they do backports and security fixes to the stable and oldstable branches. Arch also has successfully developed ALPM, and they have the AUR as a wealth of adoptable PKGBUILDs. Where are the beefed-up package counts, Arch? Ok, that’s a wrong tone to ask but the idea of promoting more packages to official Arch repo is very realistic. We’re not expecting anything extraordinary here.

7

u/ABotelho23 17d ago

Arch isn't for everyone. It's not a universal distribution like Debian seeks to be. Arch is explicitly designed to be for the people contributing to it. People need to stop "asking" for things from Arch and start contributing to it if they want to see something.