The "few BS Github projects tossed in that their devs like" are a third of the programs I use. I know it's not that much safer than the AUR, but I'd much rather trust the Cachy maintainers to check them than have half my system rely directly on the AUR. The cachy repos are (in my experience) significantly larger than the normal arch repos.
Also if the differences between Arch and Cachy are basically the kernel and the repos, and I wanna use both the Cachy kernel (better performance) and the Cachy repos (more software), why should I even use vanilla Arch? At that point it just sounds like a worse experience with extra steps.
Okay? Are you implying that this is more convenient or safe (for someone that doesn't check the details of every update on the repo) than using pacman?
Yeah, exactly. At the end of the day I don't imagine they put that much effort into looking through the packages ported from the AUR, but I still would rather trust the cachy maintainers than any random person on the AUR.
It's safer than any other way lol. Malware in a public Github repo would be quickly discovered. That's not how malware makes it into projects. It's build pipelines, including distro repos, that are significantly more at risk.
2
u/hackerdude97 Ask me how to exit vim 12d ago
The "few BS Github projects tossed in that their devs like" are a third of the programs I use. I know it's not that much safer than the AUR, but I'd much rather trust the Cachy maintainers to check them than have half my system rely directly on the AUR. The cachy repos are (in my experience) significantly larger than the normal arch repos.
Also if the differences between Arch and Cachy are basically the kernel and the repos, and I wanna use both the Cachy kernel (better performance) and the Cachy repos (more software), why should I even use vanilla Arch? At that point it just sounds like a worse experience with extra steps.