• Pumpkin Escobar
    link
    fedilink
    English
    920 hours ago

    I start to wonder if we need something sitting between extra and aur, few more trusted maintainers and well secured update process that’s more than the aur Wild West

    Also, some sort of yay hook to do some scanning for suspicious diffs and warning or skipping those packages…

    I don’t want / need a system where I can blindly update everything, but something to help me avoid having to visually check every package diff would be nice

      • Cethin
        link
        fedilink
        English
        29 hours ago

        Their first option is possible for sure. Just something like the AUR, but that you need a proven record (either on the AUR or on something else) to post. That shouldn’t be too hard.

    • Bobby Turkalino
      link
      fedilink
      English
      318 hours ago

      I feel like this could be a use for LLMs that isn’t slop. It’s not going to catch everything of course but I imagine it would be a whole lot better than nothing