On 8/8/26 5:59 AM, CraftingDragon007 wrote:
Zen browser (zen-browser-bin) also would be nice. It may not be as popular (still over 300 votes), but it's still a browser that many people enjoy using. And as it's still in beta it often gets updates, so it would be a hassle for users to always have to update it themselves. Compared to firefox zen browser comes with better default privacy settings and without telemetry. It also looks more modern and allows the user to customize it more in depth.


On August 8, 2026 12:43:35 AM GMT+02:00, Michael Shaw <[email protected]> wrote:

        I've added librewolf to [extra] now.

        I believe reducing the amount of AUR packages people need is the
        most effective
        way to deal with the inherent malware risk the AUR has.


    I definitely agree with this approach. Is it possible to add other
    popular browsers from the AUR into extra? Brave, to me, seems like an
    excellent candidate to be moved. The fact that it isn't makes me feel
    there's a good reason why, I'm just not sure of it yet.


Please, direct the blame to the right people.

Neither the unfortunate attack waves nor the fact that zen browser is not technically suitable for official repositories is Arch maintainers' fault. Don't make it an Arch Linux specific issue either, not including beta software in official distribution repositories is a pretty common rule. It's not like zen browser is currently widely distributed in other distributions' *official* repositories either [1].

On a side note, allow me to remind that there are certain expectations toward users when using the AUR. In theory, trivial "$pkgver" bump (which is seemingly the only thing that's needed to update the zen browser PKGBUILD to the latest version at the moment) shouldn't be an insurmountable blocker to perform on a small period of time while we're working on putting the platform back on track after such unfortunate and unpredictable events. I understand that is a delicate / annoying situation, but the fact that some users' personal workflow relies on zen browser which is a *beta* software and therefore defacto shipped via the *unofficial / unsupported* user repository (with all the potential consequences it may imply) is not something we can fairly be held responsible for in my opinion...

We're aware of the consequences of the AUR being in read-only / maintenance mode, it's unfortunate and we're sincerely sorry for the inconvenience. But please keep in mind that this is the result of a mass attack that we are suffering from as well. We're working hard and doing what we can to act on it as fast as possible (which, as a reminder just in case, is done on a volunteer basis).

This is painful for everyone. Please, bear with us and be comprehensive...

[1] https://repology.org/project/zen-browser/versions

Regards,
Antiz / Robin Candau


--
Regards,
Robin Candau / Antiz

Attachment: OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to