Maarten is right on both counts, and I take them.

The defect detail belonged in the project's issue tracker, not on this list.
The maintainer has the full material, and anything further I find goes
there.

The wording was the bigger mistake. I wrote in the tool's own internal terms
without explaining a single one. If a paragraph only parses for the author
of
the code, it has no business on a list of several hundred people - that is
on
me, not on the reader.

One point from the original thread does belong here, in plain words. The
advice
we give users is "read the PKGBUILD", but what runs as root also includes
the
install scriptlet and any patch files committed next to the recipe. A tool
that
reads only the recipe matches the advice and misses the attack. Whatever the
AUR ends up blessing, that is the gap worth closing.

Alexander Berg

Reply via email to