Yeah, there’s a tool already that almost everyone already has, it’s called
your eyes and your brain. Reading the PKGBUILD is what you should be doing.

On Sat, Aug 8, 2026 at 6:24 PM doublemiu <[email protected]> wrote:

> Im not programmer but is there a way of making aur packages something more
> a like reproducable? I mean dont let pkgbuild dowload and install
> dependencies just check what are installed what are not, and force user to
> install them manually so we know what are we installing ( like istalling
> yay for first time). For me ideal situation would be mandatory
> reproducability of aur packages forced on maintainer...am i insane? If i
> understand good -bin packages are already compiled so is there any tool i
> can use to check its 1 to 1 validity with code?
>
>
>
> Sent from Proton Mail <https://proton.me/mail/home> for Android.
>
>
> -------- Original Message --------
> On Saturday, 08/08/26 at 21:29 noexec <[email protected]> wrote:
>
> Moving common packages to the extra repos is a good way to reduce AUR
> concerns; but it doesn't address the core issues. The AUR concept itself is
> sound; and user-focused packages are necessary for a project like this.
> However, the AUR lacks a trust system that distinguishes between
> contributors with 8 months of history and those with 1 day; and this
> applies to both adoptions and new packages. New maintainers should be more
> scrutinized, not by their registration date, but when they start
> maintaining; and dismissing this by saying "users need to read the
> PKGBUILD" is irresponsible; especially when some AUR team members have
> publicly downplayed the importance of timely package security updates like
> browsers and expect users to manually rebuild every PKGBUILD they depend on
> outside of official update channels, demonstrating a troubling disconnect
> from practical security needs. Creating new scanners for specific campaigns
> only perpetuates a cat-and-mouse game. The signup captcha can be trivially
> bypassed with a simple script; and there's no captcha on login, making it
> easy to mass-login or signup accounts with rotating proxies and do any
> action. Simply shutting down the AUR without fixes won't help. This was
> tried before with a lazy commit that removed dot and plus tricks from
> emails; which wouldn't have fixed the real issues anyway
> https://github.com/archlinux/aurweb/commit/1086c17bc8ba925fc2a1807b40fa01dd701da1f6
> Finally; "Antiz" has used his trusted user access to post to personal AUR
> packages when the AUR was down.
>
> Note: This message was translated.
>
> On Thursday, August 6th, 2026 at 8:42 AM, doublemiu <[email protected]>
> wrote:
>
> Hello. I just would like to ask about chances of migrating most popular or
> maintened by developers packages to community repository? Idea we still
> have to upgrade such packages like zen browser, heroic games launcher and
> many others from aur ...
>
>
>
>
> Sent from Proton Mail <https://proton.me/mail/home> for Android.
>
>
>

Reply via email to