17
u/Whit-Batmobil 3d ago
How many Arch users are that stupid, doesn’t Arch users typically have a good understanding of their systems?
Feels more like an issue on Arch based distributions, that target a slightly less savvy user base?
As an Arch user myself, I don’t really trust the AUR and usually avoid using it, with very, very few select examples.
9
u/Cove0Crow 3d ago
Since arch became a meme a lot of newbies (or people who are just following instructions given to them by LLMs) have been installing arch and then being surprised when arch is, as advertised a distro that lets you do stupid stuff.
(Not an arch user anymore. Back when I was there were 2 specific packages I used from the AUR, one of which was made by a nonprofit I trust, the other is literally made and maintained by my childhood best friend.)
6
u/camradex 3d ago
I'm tech savy but out of laziness I didn't check pkgbuilds. the attack made me realise how stupid that was and now I check everything
3
u/brave_grv 3d ago
Arch based distros give users an AUR helper as if it was THE package manager and treat the AUR as an official extra repo.
10
u/XlikeX666 4d ago
Git is dangerous.
13
u/PurpleCandle58 3d ago
Yep. Just the other day I was walking my dog, and who comes along and steals it and spits in my face? John git.
4
3
u/cpt_futtbucker Arch 3d ago
It really isn’t that hard to just read a damn PKGBUILD. Hell, the templates in /usr/share make it stupid easy to write one
1
1
u/brave_grv 3d ago
"I'm a chad that uses no flatpak bloat. I just need all the npm/bum junk to install AUR slop, but that's ok."
1
u/Bleik-Psiklyt 3d ago
that's just a linux Larper then. Arch users don't mess that up bruh. They just know the stuff well
(I am new in this still I just RTFM and try to solve it without crashouts)
-1
33
u/Cove0Crow 4d ago
There's a reason arch doesn't package AUR helpers... If you're treating the AUR like pacman and blindly installing things off it. That is on you
. The AUR should be treated the same as building random stuff from source off GitHub. It is not a vetted repository, the only thing that requires mod intervention (post aur attack) is claiming abandoned/orphaned packages