I believe I've already sead this before somewhere else but I guess I'll say it again.
The thing is I'm going to say is that something like Socket [socket.dev] looks good. The problem is that it doesn't run locally. If we can depend less on the outside world, especially for something like the AUR I think that could be a good thing. And I should add on to this statement above. That because it is not open source it is not a good idea to add it to the AUR. I completely agree that the AUR needs some sort of protection like socket but socket is not the answer. An open source solution will work a lot better for us. A dependence on something non open source for the AUR is a bad idea. note that I'm not AUR staff. I'm just giving my dime on this. Best regards. Please note that a PGP key may be assigned to my email. If this key does not match in between my emails it is a fake email and should be disregarded. Sent with proton mail. On Wednesday, August 12th, 2026 at 8:39 AM, Cynthia <[email protected]> wrote: > On 11/08/2026 20:04, Sean E. Russell wrote: > > yay asks me if I want to view the diffs every time I install or upgrade > > something, unless I choose `--noconfirm`. I don't recall having to configure > > anything to get this behavior. > The difference is in the defaults; by default unless you explicitly ask > to see the diffs of packages, it doesn't show them and proceed to > install. Paru on the other hand shows by default until you tell it not > to. It's a subtle difference, but the devil's in the details especially > when it comes to habits. > > I prefer Paru's defaults there, as it requires explicit dismissal to > skip the review step. Reviewing PKGBUILDs should always be the default, > and one of my biggest gripes with Arch derivatives is their habit of > exposing inexperienced users to the AUR without informing users of the > mandatory due diligence expected from them in order to safely use the AUR. > > ~Cynthia >
publickey - [email protected] - 0x55011640.asc
Description: application/pgp-keys
signature.asc
Description: OpenPGP digital signature
