Karna@lemmy.ml to Linux@lemmy.ml · 24 hours agoArch Linux Users at Risk Again as AUR Hit by Another RATnews.itsfoss.comexternal-linkmessage-square23fedilinkarrow-up1101arrow-down13cross-posted to: linux@programming.dev
arrow-up198arrow-down1external-linkArch Linux Users at Risk Again as AUR Hit by Another RATnews.itsfoss.comKarna@lemmy.ml to Linux@lemmy.ml · 24 hours agomessage-square23fedilinkcross-posted to: linux@programming.dev
minus-squareKarna@lemmy.mlOPlinkfedilinkarrow-up19arrow-down1·23 hours agoFlatpak does have a concept of Verified Publisher. Many distros ship flatpak app store with default filter set to Verified Publisher only.
minus-squareDaniel Quinn@lemmy.calinkfedilinkEnglisharrow-up16·23 hours agoThat sounds like a nice feature we could use for the Aur actually. We already have the votes value, but some sort of verification body could help rescue the Aur’s reputation.
minus-squareCricket [he/him]@lemmy.ziplinkfedilinkEnglisharrow-up5·19 hours ago Many distros ship flatpak app store with default filter set to Verified Publisher only. Also, if your distro doesn’t do this, you can do it yourself. You can modify, for instance, KDE Discover’s flathub repo to use the verified subset.
Flatpak does have a concept of Verified Publisher. Many distros ship flatpak app store with default filter set to Verified Publisher only.
That sounds like a nice feature we could use for the Aur actually. We already have the
votes
value, but some sort of verification body could help rescue the Aur’s reputation.Also, if your distro doesn’t do this, you can do it yourself. You can modify, for instance, KDE Discover’s flathub repo to use the verified subset.