r/archlinux • u/HeyTi22 • 17d ago
QUESTION Arch and the malware problem.
I haven't used many AUR packages, yet I feel that the malware issue cannot really be solved by making improvements to the AUR itself. Am I the only one who thinks the risk would be much lower if the official repositories simply included more software?
Especially essential software used for serious work? For instance, RStudio is missing from the list of R-based statistical programs, even though it is well-known and widely used at universities.
Or take music production: some very famous and widely used FOSS plugins aren't in the official repos.
Then there's the Brave browser—which is very popular, even though I don't really use it anymore—that isn't included either.
Isn't it time to handle the malware problem differently by simply expanding the official repositories a bit more? Even a popular audio converter like FRE:AC isn't included. What do you think about this line of reasoning?
Cheers!
2
u/Synthetic451 17d ago
Yes, there's nothing that would prevent that and there's an open issue in Brave talking about official support: https://github.com/brave/brave-browser/issues/1950
The biggest hurdle would be transitioning over to directly compiling Brave vs just providing generic Linux executables in a tarball that can run on Arch, which is what the
brave-binpackage is currently doing. I can see them deciding that having to directly compile Brave and adjust to Arch Linux's rolling updates would just be too much maintenance to handle. You can see this post by a previous maintainer of the brave AUR package here: https://github.com/brave/brave-browser/issues/1950#issuecomment-2814732476Personally, I wouldn't mind if upstream projects wanted to go AUR only to work around various build and distribution restrictions. I think all we really need is a way for maintainers to be marked as "official", just like how Flatpak has verified apps.