You are not logged in.
Arch Linux is my favorite Linux distribution due to the minimalism it offers, allowing me to build my system exactly how I want it. However, I have concerns about security when downloading packages from the AUR. I always make sure to carefully review the package build scripts.
I would like to know if there is any kind of validation or review process before a package is submitted to the AUR. Are packages held for a while for checks before being made available? Additionally, I'm interested in learning about best practices for securely downloading packages from the AUR.
Offline
Nope. There are packaging guidelines, and while failure to comply with them may result in a package being removed from the AUR, it doesn't prevent them being submitted in the first place. The AUR is governed by a small team of volunteer 'trusted users' (now called Package Maintainers) who mostly rely on user-submitted reports and mailing list messages to alert them to possible problem packages/users.
See also: https://wiki.archlinux.org/title/Arch_User_Repository
Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD
Making lemonade from lemons since 2015.
Offline
Additionally, I'm interested in learning about best practices for securely downloading packages from the AUR.
I'd say best practice is doing what you are already doing, i.e. check the PKGBUILD before building and installing the package.
Last edited by Fuxino (2024-03-02 18:29:21)
Offline