105
The security situation with the Arch Linux AUR got a lot worse
(www.gamingonlinux.com)
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
I have no idea about the stance of CachyOS on AUR packages.
I totally agree with you, establishing trust is not an easy problem. I don't expect the average joe to understand shell scripts. I would put myself in that categorie as well. This one however was simple enough that it seemed okay to me. If I don't understand what's going on in a script I am really careful and try to avoid it, if possible. I still wouldn't consider them universally bad. For some things it is even the recommended install option. I vaguely remember some things in the Raspberry Pi universe ( IIRC this was even the case for Docker in the past).
There are multiple factors which can lead to trust. Maybe you know the CachyOS forum and how well it is maintained. How old is the account etc.. But as you said, there are always risks. The account could be compromized as well. But most of that isn't specific to shell scripts or Linux in general. You shouldn't install an application from some shady website in Windows either.
What is your recommended way to deal with the current situation?
What do you think this does, in bash: