• Cease@mander.xyz
    link
    fedilink
    English
    arrow-up
    22
    arrow-down
    5
    ·
    1 month ago

    I think a lot of people are confusing what the AUR actually IS. It is NOT the official package repository used by Archlinux - it’s more like a bunch of community install scripts for stuff that isn’t officially supported yet - for popularity or other reasons.

    So for all those people complaining and saying “debian does it better” it’s very likely that you would not even HAVE a package to install and would have to come up with a build script on your own - the AUR allows you to skip this and instead just verify that the script itself isn’t malicious, which is usually fairly obvious.

    A lot of people here seem to be under the impression that all of this effort should be abstracted for them - but that’s what you chose when you left windows - a system that you control intimately with a necessitation to actually do some upkeep yourself because a giant company isn’t doing it for you.

    In other words. RTFM and stop expecting other people fix all your problems for you, because that’s exactly how windows got to how it currently is.

    • Jjakef96@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      I haven’t been on my PC that much this week, just Friday night. And our D&D group uses Discord so I needed to make sure it was up to date to ensure it would run. I typically just do a, “sudo pacman -Syu” and that seems to update what I need.

      If that is the only thing I did with the PC during this window, is there any concern?

      • flop_leash_973@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        1 month ago

        Probably not. The article says that most of it seems to have come from orphaned stuff in the AUR that the threat actors took ownership of via the legit process, then modified to pull down malicious NPM packages when someone went to install them.

        So if your Discord package is well maintained you probably have nothing to worry about.