惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
S
SegmentFault 最新的问题
V
Visual Studio Blog
J
Java Code Geeks
宝玉的分享
宝玉的分享
美团技术团队
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
有赞技术团队
有赞技术团队
量子位
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
博客园 - 叶小钗
月光博客
月光博客
P
Proofpoint News Feed
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
博客园_首页
腾讯CDC
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog

LWN.net comments

tcmalloc's weird hack [LWN.net] Fixed? [LWN.net] mpd [LWN.net] Userspace AX.25 [LWN.net] RIP [LWN.net] My two cents... [LWN.net] pipx [LWN.net] Tragedy [LWN.net] A young man destined for glory [LWN.net] And 'less' won't let you search [LWN.net] A great loss [LWN.net] Sad and shocking news [LWN.net] Easy migration from Clementine [LWN.net] Sad coincidence [LWN.net] GNOME is actually usable thanks to Seth et al [LWN.net] Sad news :( [LWN.net] armhf supports preempt_rt [LWN.net] MusicBrainz accurracy [LWN.net] On open source maintainership [LWN.net] Let's stop here [LWN.net] Not a new thing [LWN.net] uv is indeed great pgmoneta Some comments on this on a Postgres blog feed [LWN.net] uv [LWN.net] going to Debian [LWN.net] Upgrading 64-bit-capable systems to 64-bit kernels? [LWN.net] Free Software foundations Maintainers can wait for code review but not for publish review? A reasonably extreme point of view [LWN.net]
Code review [LWN.net]
hmanning77 · 2026-06-22 · via LWN.net comments

I agree with you here. Reading the phrase "Even careful, security-minded people are unlikely to review every single update to a PKGBUILD" made me want to wave my hand in the air and yell, "That's me! I do review every update!"

It's so frustrating because the practice of blindly installing from the AUR is so obviously a bad idea, so clearly documented as something you shouldn't do, and so thoroughly unsupported by the official Arch project, but clearly a common practice anyway. It's a case of "this is why we can't have nice things", and I'll be really frustrated if the AUR has to be constrained or shut down because people can't use it responsibly.

Unfortunately, I don't know the answer. You can't simply admonish people to " be responsible". The Arch project tries to communicate the nature of the AUR by refusing to make it easy to use (the canonical procedure is "git clone, review, and build manually"), but you can't stop people from automating away that barrier, at which point people get told to "just use a helper".

An education campaign? After all, that might happen on it's own eventually, if a suitably big attack occurs and the misguided "just use a helper" advice turns into misguided "the AUR is full of malware" advice.