Yeah, there’s a tool already that almost everyone already has, it’s called your eyes and your brain. Reading the PKGBUILD is what you should be doing.
On Sat, Aug 8, 2026 at 6:24 PM doublemiu <[email protected]> wrote: > Im not programmer but is there a way of making aur packages something more > a like reproducable? I mean dont let pkgbuild dowload and install > dependencies just check what are installed what are not, and force user to > install them manually so we know what are we installing ( like istalling > yay for first time). For me ideal situation would be mandatory > reproducability of aur packages forced on maintainer...am i insane? If i > understand good -bin packages are already compiled so is there any tool i > can use to check its 1 to 1 validity with code? > > > > Sent from Proton Mail <https://proton.me/mail/home> for Android. > > > -------- Original Message -------- > On Saturday, 08/08/26 at 21:29 noexec <[email protected]> wrote: > > Moving common packages to the extra repos is a good way to reduce AUR > concerns; but it doesn't address the core issues. The AUR concept itself is > sound; and user-focused packages are necessary for a project like this. > However, the AUR lacks a trust system that distinguishes between > contributors with 8 months of history and those with 1 day; and this > applies to both adoptions and new packages. New maintainers should be more > scrutinized, not by their registration date, but when they start > maintaining; and dismissing this by saying "users need to read the > PKGBUILD" is irresponsible; especially when some AUR team members have > publicly downplayed the importance of timely package security updates like > browsers and expect users to manually rebuild every PKGBUILD they depend on > outside of official update channels, demonstrating a troubling disconnect > from practical security needs. Creating new scanners for specific campaigns > only perpetuates a cat-and-mouse game. The signup captcha can be trivially > bypassed with a simple script; and there's no captcha on login, making it > easy to mass-login or signup accounts with rotating proxies and do any > action. Simply shutting down the AUR without fixes won't help. This was > tried before with a lazy commit that removed dot and plus tricks from > emails; which wouldn't have fixed the real issues anyway > https://github.com/archlinux/aurweb/commit/1086c17bc8ba925fc2a1807b40fa01dd701da1f6 > Finally; "Antiz" has used his trusted user access to post to personal AUR > packages when the AUR was down. > > Note: This message was translated. > > On Thursday, August 6th, 2026 at 8:42 AM, doublemiu <[email protected]> > wrote: > > Hello. I just would like to ask about chances of migrating most popular or > maintened by developers packages to community repository? Idea we still > have to upgrade such packages like zen browser, heroic games launcher and > many others from aur ... > > > > > Sent from Proton Mail <https://proton.me/mail/home> for Android. > > >
