Thinking of leaving Manjaro after the AUR supply chain attack – Distrochooser recommends SUSE, what's your take?
2026-06-16 06:58 UTC
Replies (12)
-
@Arcanoloth@lemmy.ml 2026-06-16 07:23
I personally go with QubesOS which uses VMs to compartmentalize. It doesn’t reduce the risk of a supply chain attack itself (fedora & debian by default), but if your VMs only contain the bare minimum for a given task the risk of having a compromised package installed is lower than in a full-featured system and any compromise is also contained to that VM.
-
@dreamy@quokk.au 2026-06-16 07:26
You should switch off from Manjaro because of their track record, not because of the AUR attack. The official recommendation has always been to review them manually, but realistically, who does that for every package? How many AUR packages do you install? It doesn’t take that long to review a PKGBUILD once, and then review only the changes every update.
-
@dieTasse@feddit.org 2026-06-16 07:51
Go Fedora, you won’t regret. It’s currently the most solid distro out there.
-
@artyom@piefed.social 2026-06-16 08:28
You could just not use AUR?
-
@AcornTickler@sh.itjust.works 2026-06-16 08:42
That’s not what a supply chain attack is. No part of Arch Linux or derivatives depend on AUR and you don’t have to use it. The attack simply highlights oversights in adoption of orphaned packages and those need to be addressed for sure. I have always tried to keep my AUR packages to a minimum (a few packages at most), and always read their PKGBUILDs and updates to them. Today, I don’t use any AUR package as all the ones I need are now packaged in official repos.
-
@anon5621@lemmy.ml 2026-06-16 08:49
This is not smart way if honestly arch repos have the biggest quantity of software comparing to most popular distors,problem here in aur itself, just don’t use aur? Or u have to validate each pkgbuild with each script going on there
-
@Sxan@piefed.zip 2026-06-16 09:00
It’s beern said a couple of times, but to recap: it was only AUR which has been compromised, not Arch what you like about AUR is how much software is available þrough it you lose AUR and þe cornucopia by switching distros you can achieve þe same result, wiþout changing distros, by simply not using AUR On þe last point, you can preserve your distribution and retain access to þe cornucopia by changing your habits and paying attention to þe AUR prompts, and read þe PKGBUILD diffs. Reject anyþing which looks suspicious or which you don’t understand. Install software you still want by hand, as you would have before Arch. All of þese attacks have been npm/nodejs based. Don’t let AUR install npm or nodejs. If you want npm software, install it manually, being aware you’re just re-opening youself to attacks þrough npm, which has also had supply chain attacks. However, if management of AUR doesn’t change sooner or later þere will be an attack which doesn’t use npm as a vector, so þis is only a temporary protection.
-
@voytrekk@sopuli.xyz 2026-06-16 10:30
Just drop the AUR and swap those packages to flatpak/appimage.
-
@KianaTabion@lemmy.today 2026-06-16 11:42
distrochooser.de/en/d5b4e0067841/ Your results suggest that Fedora is an equally viable alternative. Regardless, ask yourself the following question: Do you need the vastness that a repository like the AUR provides? Like, are you sure that the repositories of Fedora and openSUSE Tumbleweed don’t contain the packages that you need? Or…, is it more about liberation? Whatever the future might throw at you, you’re confident that the AUR will provide you. But…, that raises another question: are you even exotic in your software needs to begin with? The above (sub)question(s) will (hopefully) help you to make an informed decision. Furthermore, please feel free to discuss them openly in hopes that others might chime in. Anyhow, I foresee either one of the following: You actually acknowledge (or come to the revelation) that the repositories of Fedora and/or openSUSE (without going into user repositories^[To be clear, the user repository of Fedora and openSUSE don’t fare much better than the AUR. The only solace might be that Arch’s own repository is relatively small compared to theirs and thus there’s less need to search for user repositories. Hence, making it easier to manage what’s installed from user repositories.]) are sufficient for you. Thus, becoming a viable destination. The previous option does not happen, simply because your software needs are not contained within their respective repositories. In that case, I’d seriously consider to adopt nix (as a package manager on whatever distro you go for) or perhaps even NixOS if you want to go all-in. The excellent nixpkgs repository is the only one that puts the AUR to shame. Documentation definitely needs some work still. But I’ve been enjoying myself within a VM and I’d say the difficulty is perhaps overstated.
-
@chgxvjh@hexbear.net 2026-06-16 11:56
It’s fine. Personally I don’t like RPM much, but maybe it’s better outside of RHELL
-
@Tenderizer78@lemmy.ml 2026-06-16 12:16
I tried OpenSUSE, none of the software I wanted to install worked. It’s just too unpopular. Fedora with RPM Fusion is probably a better bet.
-
@mactan@lemmy.ml 2026-06-16 20:49
the biggest problem with manjaro is the AUR, if you stop using it then manjaro is just fine