I believe I've already sead this before somewhere else but I guess I'll say it 
again.

The thing is I'm going to say is that something like Socket [socket.dev] looks 
good. The problem is that it doesn't run locally.  If we can depend less on the 
outside world, especially for something like the AUR I think that could be a 
good thing.

And I should add on to this statement above. That because it is not open source 
it is not a good idea to add it to the AUR. I completely agree that the AUR 
needs some sort of protection like socket but socket is not the answer. 


An open source solution will work a lot better for us. 

A dependence on something non open source for the AUR is a bad idea.  


note that I'm not AUR staff. 

I'm just giving my dime on this.

Best regards.
Please note that a PGP key may be assigned to my email. If this key does not 
match in between my emails it is a fake email and should be disregarded. 

Sent with proton mail.


On Wednesday, August 12th, 2026 at 8:39 AM, Cynthia <[email protected]> wrote:

> On 11/08/2026 20:04, Sean E. Russell wrote:
> > yay asks me if I want to view the diffs every time I install or upgrade
> > something, unless I choose `--noconfirm`. I don't recall having to configure
> > anything to get this behavior.
> The difference is in the defaults; by default unless you explicitly ask 

> to see the diffs of packages, it doesn't show them and proceed to 

> install. Paru on the other hand shows by default until you tell it not 

> to. It's a subtle difference, but the devil's in the details especially 

> when it comes to habits.
> 

> I prefer Paru's defaults there, as it requires explicit dismissal to 

> skip the review step. Reviewing PKGBUILDs should always be the default, 

> and one of my biggest gripes with Arch derivatives is their habit of 

> exposing inexperienced users to the AUR without informing users of the 

> mandatory due diligence expected from them in order to safely use the AUR.
> 

>       ~Cynthia
> 

Attachment: publickey - [email protected] - 0x55011640.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to