惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
B
Blog
Jina AI
Jina AI
N
Netflix TechBlog - Medium
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
美团技术团队
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
U
Unit 42
The Cloudflare Blog
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
Apple Machine Learning Research
Apple Machine Learning Research
I
InfoQ
GbyAI
GbyAI
腾讯CDC
MongoDB | Blog
MongoDB | Blog

LWN.net comments

tcmalloc's weird hack [LWN.net] Fixed? [LWN.net] mpd [LWN.net] Userspace AX.25 [LWN.net] RIP [LWN.net] My two cents... [LWN.net] pipx [LWN.net] Tragedy [LWN.net] A young man destined for glory [LWN.net] And 'less' won't let you search [LWN.net] A great loss [LWN.net] Sad and shocking news [LWN.net] Easy migration from Clementine [LWN.net] Sad coincidence [LWN.net] GNOME is actually usable thanks to Seth et al [LWN.net] Sad news :( [LWN.net] armhf supports preempt_rt [LWN.net] MusicBrainz accurracy [LWN.net] On open source maintainership [LWN.net] Let's stop here [LWN.net] Not a new thing [LWN.net] uv is indeed great pgmoneta Some comments on this on a Postgres blog feed [LWN.net] uv [LWN.net] going to Debian [LWN.net] Upgrading 64-bit-capable systems to 64-bit kernels? [LWN.net] Free Software foundations Maintainers can wait for code review but not for publish review? A reasonably extreme point of view [LWN.net]
Code review [LWN.net]
hmanning77 · 2026-06-22 · via LWN.net comments

I agree with you here. Reading the phrase "Even careful, security-minded people are unlikely to review every single update to a PKGBUILD" made me want to wave my hand in the air and yell, "That's me! I do review every update!"

It's so frustrating because the practice of blindly installing from the AUR is so obviously a bad idea, so clearly documented as something you shouldn't do, and so thoroughly unsupported by the official Arch project, but clearly a common practice anyway. It's a case of "this is why we can't have nice things", and I'll be really frustrated if the AUR has to be constrained or shut down because people can't use it responsibly.

Unfortunately, I don't know the answer. You can't simply admonish people to " be responsible". The Arch project tries to communicate the nature of the AUR by refusing to make it easy to use (the canonical procedure is "git clone, review, and build manually"), but you can't stop people from automating away that barrier, at which point people get told to "just use a helper".

An education campaign? After all, that might happen on it's own eventually, if a suitably big attack occurs and the misguided "just use a helper" advice turns into misguided "the AUR is full of malware" advice.