← Back to context

Comment by rcxdude

6 hours ago

Most PKGBUILDS are stupidly simple, they're probably easier to read than a set of tool calls. See this for a randomly picked recently updated example:

https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=batte...

(honestly I think the way that arch packages work is really nice compared to most other distros: you can almost copy and paste the README of a project into one and have a package)

Here's the most complicated one I found, building a browser:

https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=flowf...

The main risk, if you're reading them, is typosquatting and hiding the malicious code in what the project downloads.