09-23-2020, 08:13 AM
(09-21-2020, 07:58 AM)as365n4 Wrote: And there is a difference between a random repo found on the Internet and a mainline Arch or Debian repo as one can not directly upload a package without being a Maintainer or Developer in the first place or have to know a Sponsor which can upload for one.
Except absolutely anyone can upload anything to the AUR. The process does not require any form of approval, assessment or supervision. I've seen a lot of very badly written PKGBUILDs there.
This is somewhat mitigated by the fact that comments for each PKGBUILD in the AUR are centralised and public, but this is hardly a strong protection.