• istdaslol@feddit.org
    link
    fedilink
    arrow-up
    3
    arrow-down
    2
    ·
    2 days ago

    i wouldnt know where to get the info in the first place. when i use windows update i also dont reed any changelog because that shouldnt be the users job but the suppliers

    • Aatube@kbin.melroy.org
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      windows update doesn’t force you to take a look at the changelog. most AUR helpers do so you better bet that it’s important

    • Ghoelian@piefed.social
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 days ago

      The whole point of the AUR is that it’s just random people’s code. There is no supplier here. If you don’t know where to find that information, you really shouldn’t be using AUR.

      • istdaslol@feddit.org
        link
        fedilink
        arrow-up
        2
        ·
        2 days ago

        In an ideal world yes, but I needed some software that was only available via AUR and if the official guides tell me I can install it via AUR I will.

        • Aatube@kbin.melroy.org
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          that is indeed the official guides’ fault if they’re not in charge of helping maintain the AUR package. not the case for most of the infected packages here other than notably alvr, though.

    • Vendetta9076@sh.itjust.works
      link
      fedilink
      arrow-up
      7
      ·
      2 days ago

      As an avid user of the AUR, you’d be correct if you were downloading from the official arch repository. But you aren’t. AUR is basically like downloading from github. The only “guarantee” you get is from whoever put the package up and its up to you to determine if they’re trustworthy.