• Ricaz@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    10
    ·
    15 hours ago

    It’s a USER repository, where you literally download install files from unverified strangers.

    There’s a reason all the AUR helpers prompt you to verify all the files before they will build or install anything.

    • fruitcantfly@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      10 hours ago

      I wonder percentage of Arch users are actually capable of verifying that an AUR package is safe to install. I doubt that the number is very high, especially with the growing popularity of the distro