← Back to context

Comment by virajk_31

7 days ago

AUR doesn't guarantee security, its upto the user to use AUR & verify before installing anything, its very evident why arch is not used in enterprise solutions.

Arch is not used in enterprise solutions because of the AUR? Can't you just not use it?

  • AUR is choice, rolling release is the reason

    • No, it's not. If Debian had a community-maintained repo of additional packages, the same thing could happen there.

      The fundamental problem is having something that has very loose oversight and next to no controls. That may have worked in the past, but in the day and age of constant supply chain attacks, it's a major liability.

      2 replies →

    • Rolling release has nothing to do with this. It could just as well be a PPA in ubuntu or any deb repo for debian or similar.