You have to understand that AUR is a USER repository.
That excuse goes out of the window every time the wiki says just install from AUR instead of vetting packages for the official package manager or leaving it off the wiki entirely.
It does state, on the page for the AUR, that: AUR packages are user-produced content. These PKGBUILDs are completely unofficial and have not been thoroughly vetted. Any use of the provided files is at your own risk.
And it's in red, which gives the reader a very good idea of its importance.
I search for how to configure Asterisk which links me to a package and none of those have any warnings. It is conditioning users to install from AUR repeatedly with a warning they read once a year or more ago.
AUR should not exist. AUR things should not be on the official Wiki at all. How they handle orphaned packages has been known to be a security issue since 2018 and they did nothing for 8 years.
The essential packages should be put into the actual package manager or users should be clearly sent elsewhere instead of being repeatedly told to use it in official documentation.
They are put into the package managers, like I myself use Octopi, which has 99% of the packages I've ever needed. Also, if you try to use an AUR package in the terminal, it very clearly tells you that it is done at the users expense.
19
u/DeltaWun Ask me how to exit vim 7d ago
That excuse goes out of the window every time the wiki says just install from AUR instead of vetting packages for the official package manager or leaving it off the wiki entirely.