Hi Emiliano,

> what do you mean by "handled like AURweb"?

sorry for the confusion. I did not want to refer AURweb specifically but use it as an example. Probably not a good idea. I wanted to state that a security enhancing component such as trustsight probably should be seen as kind of "AUR infrastucture component". If it cannot be "built in" (in AUR helpers), then it probably should be a repo package, not a PKGBUILD.

But it could be a proposal to include it in AUR helpers. All it's functionality is available programatically. All that obviously is up to AUR maintainers and TUs. I'm just expressing my vote to make such tool part of how AUR works more securely. It seems to be an easy/quick win. Especially as it does not block other measures that were discussed here.

Olav

Reply via email to