this post was submitted on 16 Jun 2026
180 points (98.9% liked)

Linux

14018 readers
399 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] fruitcantfly@programming.dev 4 points 2 days ago* (last edited 2 days ago) (7 children)

AUR is not unique in being a user repository, but it seems somewhat unique in having basically zero oversight. Which is a bad idea for reasons that should be painfully obvious by now.

For comparison, Gentoo's GURU repository allows everyone to submit packages, but limits the ability to accept these submissions to a subset of trusted users

[–] kieron115@startrek.website 0 points 2 days ago* (last edited 2 days ago) (5 children)

GURU bills itself as an official repository that's user-maintained. AUR makes no claims of being official as far as I can see from their website.

[–] fruitcantfly@programming.dev 4 points 2 days ago (4 children)

The AUR domain is aur.archlinux.org and it is linked from the menu-bar on archlinux.org. If AUR is not official, then the Arch sure is sending mixed signals to its users

[–] kieron115@startrek.website 0 points 2 days ago (1 children)
[–] fruitcantfly@programming.dev 2 points 2 days ago* (last edited 2 days ago)

Which is not much different from the disclaimer about GURU, though GURU does a much better job at explaining the risks involved in using it:

Disclaimer

Please note that the GURU project is maintained and reviewed entirely by Gentoo users. It is only subject to minimal supervision from individual Gentoo developers, and is not supported by projects such as Gentoo Security. While our Trusted Contributors do their best to keep GURU safe, it is possible for it to contain vulnerable, badly broken or even malicious software. You are using it on your own responsibility.

load more comments (2 replies)
load more comments (2 replies)
load more comments (3 replies)