I don't mind people vibe coding Linux utilities, but do you really gotta upload it to the AUR?
Just an example, one of many. Check the upstream. Four months old. Two contributors: some human and an orange asshole. Human has no other repositories, so I guess the asshole is the more trustworthy one.
I'm assuming this is just some vibe coded bullshit where someone just said yes to everything Claude asked. I'd read the code to confirm it's not malicious but this person has already wasted enough of my time already.
Anyway AUR is not going to survive the Eternal Sloptober.
5 replies
AUR was never trustworthy. It leans very much towards the convenience end of the security-convenience spectrum.
This annoys me as well. And its not just AUR either, I hit this with pi.dev plugins, which are in NPM:
https://pi.dev/packages?name=permissions
Look how many duplicates there are, just because one person mildly changed am existing one, and never contributed back instead.
People are publishing their slop projects as if they intend on maintaining them, but they clearly aren't capable or willing to actually maintain them.
The only thing on the AUR is a recipe to build the package on arch. In a perfect world, the AUR contains a build recipes for every package in existence. It's always up to the user to be discerning about what they install on their system.
Why shouldn't they? They are using aur as intended, repository for user provided package recipes.
Exactly. The way I see it, AUR is the Wild West where anything goes. There are good, bad and ugly packages so you better know what you’re doing when installing those.