logoalt Hacker News

ajrosstoday at 1:50 PM2 repliesview on HN

While true, tarring Arch here is a little unfair. AUR isn't enabled by default. It can't even be used via the same package front end, and in fact the "official" usage model requires that you clone the source yourself.

Indeed, AUR is bad as a software distribution mechanism (really it's best understood as a proving ground for baby packages before they get real maintainers and distro blessing), but it's less bad than NPM which puts the malware in the trusted/default/automated path.


Replies

matheusmoreiratoday at 2:15 PM

I'm not tarring Arch, I was praising it. I made sure to explicitly spell out the "User Repository". Arch is the one that does it right.

Ancapistanitoday at 1:52 PM

I didn’t take it that way at all - rather, Arch is the only one that does it “right” with the AUR.

show 1 reply