• misterrabbit@lemmy.world
    link
    fedilink
    English
    arrow-up
    39
    ·
    1 day ago

    Been saying for years that people need to stop treating the AUR like a repo, when it’s more akin to curl installscript.sh | bash.

    • Cethin@lemmy.zip
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      2
      ·
      1 day ago

      But it is a repo. It’s just an unofficial one. I don’t know how you use it without understanding this. It’s not far from perfect, but it is useful.

      • gergo@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        1
        ·
        1 day ago

        the problem is exactly the fact that it is a repo; it introduces a layer of unknown between the dev and the user. and the user will unavoidably “trust” it (especially when it’s listed amongst official repos in e.g. the graphical version of Pamac), without understanding the risks.