Post #4282915
2026-07-31 15:38 UTC
Replies (3)
-
@trevor@lemmy.blahaj.zone 2026-07-31 16:22
Enforced commit signing and making it obvious when the signature changes would help make adoption much safer. I really hope they implement it.
-
@Dirk@lemmy.ml 2026-07-31 17:03
The problem is the current implementation Yes, exactly this! I am not surprised it happens. I’m surprised it didn’t happen before. especially new accounts Weren’t there “sleeper accounts” registered years ago that became active in the current wave? Also the AUR helpers should do a better job. Even experienced people will just update as if nothing could happen. Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.
-
@lemmyvore@feddit.nl 2026-07-31 20:15
They should find a better solution Who’s “they”? Because it’s not Arch. Arch doesn’t want to have anything to do with AUR, and neither does any of the Arch-derived distros. They’re all perfectly happy taking advantage of it, of course, but not the responsibility.