I was arguing that the AUR shutting down without any real plan forward was 
irresponsible from a security updates perspective, and the fact that last time 
it shut down registrations for 2 weeks just to add that simple vibe-coded 
commit shows a lack of real changes or a plan forward for the AUR; I think 
"lazy" was an understatement since you then released an announcement acting 
like the AUR was now safer.

My proposal, which many people have already talked about primarily outside of 
the AUR mailing list, is a trusted user system. weighted factors of their 
maintaining history and integrating some level of trust system. While not 
perfect, it would help flag what needs review to the users; as you said, it's 
the "Arch User Repository."

This trusted system, captchas, and basic modern signup and sign-in features are 
not putting much weight on the nearly 60 volunteers and trusted users.

There's another issue with the current system and how packages are removed and 
banned when infected: there's no warning on the page that they were previously 
infected. The trusted user who revoked it might show as the last publisher 
temporarily until a new maintainer is found, but there's no indicator that it 
was infected. An open, viewable log of all changes to a package would fix this 
completely since all users can independently verify, and then it can be 
extended to AUR helpers to implement, which can pull the same info.

I mentioned you updating personal projects only due to you shutting down the 
AUR for everyone else, for much more security-needed packages than system tray 
applets.

Note: This message was translated.

On Saturday, August 8th, 2026 at 8:28 PM, Robin Candau <[email protected]> 
wrote:

> On 8/8/26 8:53 PM, noexec wrote:
> > Moving common packages to the extra repos is a good way to reduce AUR 
> > concerns; but it doesn't address the core issues. The AUR concept itself 
> > is sound; and user-focused packages are necessary for a project like 
> > this. However, the AUR lacks a trust system that distinguishes between 
> > contributors with 8 months of history and those with 1 day; and this 
> > applies to both adoptions and new packages. New maintainers should be 
> > more scrutinized, not by their registration date, but when they start 
> > maintaining; 
> 
> We're not lacking ideas, we're lacking human resources with enough free 
> time to implement them and that are also willing to maintain / feel 
> responsible for them over time. Are you volunteering?
> 
> > and dismissing this by saying "users need to read the 
> > PKGBUILD" is irresponsible; especially when some AUR team members have 
> > publicly downplayed the importance of timely package security updates 
> > like browsers and expect users to manually rebuild every PKGBUILD they 
> > depend on outside of official update channels, demonstrating a troubling 
> > disconnect from practical security needs. 
> 
> The content of the AUR always has been unsupported. Whatever people 
> submit there (regardless of how popular and/or critical they might be) 
> doesn't make it more official. The AUR always came with no guarantee, 
> having web browsers in there doesn't change that.
> I'm personally fine revising / debating about the level of expectation 
> that should be put on users, but trying to fully move the responsibility 
> on the Arch team is unfair. In the end, it still is (and should remain) 
> the Arch **User** Repository.
> 
> > Creating new scanners for 
> > specific campaigns only perpetuates a cat-and-mouse game. 
> 
> Agreed.
> 
> > The signup 
> > captcha can be trivially bypassed with a simple script; and there's no 
> > captcha on login, making it easy to mass-login or signup accounts with 
> > rotating proxies and do any action. Simply shutting down the AUR without 
> > fixes won't help. This was tried before with a lazy commit that removed 
> > dot and plus tricks from emails; which wouldn't have fixed the real 
> > issues anyway https://github.com/archlinux/aurweb/ 
> > commit/1086c17bc8ba925fc2a1807b40fa01dd701da1f6 <https://github.com/ 
> > archlinux/aurweb/commit/1086c17bc8ba925fc2a1807b40fa01dd701da1f6> 
> 
> As said earlier, we're not lacking ideas but people willing to implement 
> and maintain them. Allow me to remind that all of this is done on a 
> volunteer basis. Qualifying any actions as "lazy" is not welcomed in 
> that context.
> 
> > Finally; "Antiz" has used his trusted user access to post to personal 
> > AUR packages when the AUR was down.
> > 
> 
> Indeed, I did. I've also allowed myself to use my admin access to clean 
> up some more dangerous stuff that was reported to me following the 
> attack wave [1] as well as fixing knowingly broken PKGBUILD that was 
> reported to me as well and that therefore couldn't be fixed otherwise 
> [2][3].
> 
> Is that okay or do you have any specific concerns about this?
> 
> 
> [1] 
> https://aur.archlinux.org/cgit/aur.git/commit/?h=clmath-git&id=b4a5c9e704fb155b587c59a85d4ae7d100671a8c
> [2] https://aur.archlinux.org/packages/pkgfile-git#comment-1080839
> [3] 
> https://aur.archlinux.org/cgit/aur.git/commit/?h=pkgfile-git&id=b70ef28f23313f2d145f90a49304ae36432b38e2
> 
> -- 
> Regards,
> Robin Candau / Antiz
>

Reply via email to