153
submitted 1 week ago by cm0002@lemdro.id to c/linux@programming.dev
you are viewing a single comment's thread
view the rest of the comments
[-] victorz@lemmy.world 16 points 1 week ago

Is that preferred over other types of distributions of the application?

[-] als@lemmy.blahaj.zone 15 points 1 week ago

The flatpak has always been unofficial so many people distrust it for that reason

[-] victorz@lemmy.world 1 points 1 week ago

The signal-desktop package on Arch Linux isn't official either, I'm guessing โ€” should that not be trusted either?

[-] AcornTickler@sh.itjust.works 20 points 1 week ago

If you don't trust your distro packages, you should not use that distro. In my mind Arch Linux maintainers are way more trustworthy than a random guy maintaining the Flathub version.

[-] victorz@lemmy.world 2 points 1 week ago

If you don't trust your distro packages, you should not use that distro.

Kind of my point. How high should my trust fence be before I can't install anything at all. ๐Ÿ˜…

[-] Vincent@feddit.nl -2 points 1 week ago

Didn't Arch just have a major security issue due to their packages essentially being random guys too? (And I think the same thing could theoretically happen to most distributions?)

[-] AcornTickler@sh.itjust.works 16 points 1 week ago

No, that was AUR. Those were user-generated packages with nearly no vetting.

[-] Vincent@feddit.nl 5 points 1 week ago

Ah gotcha, that is different indeed!

[-] AngryPancake@sh.itjust.works 5 points 1 week ago

To add to that, the wiki also makes it pretty clear users should be careful. It's nice to have for packages that aren't in the main repos, so it makes sense to have it somewhat part of the distro, but it does take manual effort to install aur packages, so in my mind, that's the best way to do it.

Big red label at the top: https://wiki.archlinux.org/title/Arch_User_Repository

Windows users are out there downloading random exe files...

[-] Ooops@feddit.org 5 points 1 week ago

No. Their "here's also this unofficial repository of builds completely maintained by random community users... USE AT YOUR OWN RISK - You have been warned!" ArchUserRepository got the least used (often long abandoned) packages hijacked by some bad actors.

But "Less than 1% of the least used packages in the unofficial repository you were explicitly warned about got hijacked by people trying to infect oyur PC" would not have been an interesting headline gathering attention.

[-] Vincent@feddit.nl 1 points 1 week ago

Ah, gotcha! Well, if it's any consolation, clearly I didn't click on the clickbaity headline to read the actual low-quality article :P

this post was submitted on 08 Jul 2026
153 points (98.7% liked)

Linux

14365 readers
329 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 3 years ago
MODERATORS