That's why it's one step above. The user is given an option to read the PKGBUILD (or a diff with the cached copy if it exists), but beyond that, it's still unverified arbitrary code from an external source (the project's actual source, binaries, or packages from another repository). Packages in the official Arch repos are verified by the downstream packagers. For AUR packages, it's up to the community to moderate itself, and the user to determine whether the package is trustworthy, and I'm willing to bet that not many people do it. I certainly don't vet everything I install.
yay
, a utility to access the AUR, where users share build scripts instead of binaries. It's just one step above curl | sudo sh
in terms of security.
Not the right place to ask. Try the official forums of your distro, or one of the many Linux communities on Lemmy.
4k60/444
Is that HDR? I can tell you right now that HDR is still experimental on all Wayland compositors (Plasma seems to be the farthest along, but still not reliable), and will never be implemented in X11.
view more: next ›
Very common mistake. In fact, the name Scrotuclese also appears several times in surviving records of a different culture that lived in the area at the same time, but in reference to a completely different cautionary tale.