>You have to review the source of every PKGBUILD from the AUR you install, full stop
Believing that even a small fraction of users actually do this is deeply detached from reality.
>You have to review the source of every PKGBUILD from the AUR you install, full stop
Believing that even a small fraction of users actually do this is deeply detached from reality.
I use Arch on my dev qemu VM and actually review all changes all the time.
It is not that hard with small amount of pkgbuilds:
And most people don't ever check their car oil.
The point is that the onus is on you to do it, and if you don't then the consequences are yours to bear. Personal responsibility seems to be in short supply these days.