• ZombieCyborgFromOuterSpace@lemmy.ca
    link
    fedilink
    arrow-up
    1
    ·
    17 hours ago

    Not even. The PPAs are created and hosted by very specific maintainers with very specific packages. So you have someone to blame and a single software to clean up if things go wrong. And word spreads fast. Yes, there’s a risk, but you can sort of judge how big of a risk it is.

    Meanwhile with AUR, it’s just a giant repo in which anybody can just dump whatever. The risks are huge. If I were on Arch, I wouldn’t touch it for anything. I’d rather compile the source code myself for any software I need instead of getting it there.

      • ZombieCyborgFromOuterSpace@lemmy.ca
        link
        fedilink
        arrow-up
        1
        ·
        7 hours ago

        I’ve been a Linux user for 26 years. I made distros for hardware manufacturers. I know very well the distinctions between the AUR and the regular Arch repos and the parallel with Debian’s.

        With Arch, the problem is that the AUR is available in the first place and is very easy to enable. People, especially new users, won’t necessarily understand what they’re getting into when enabling it and getting packages from there. A lot of the advice people get online suggest to get packages from AUR. So Arch users are bound to use it at some point.

        And if you add to that the fact that the standard repo has bleeding edge package versions with minimal testing means that vulnerabilities can also get introduced. And it’s happened before. This affected Arch, OpenSUSE Tumbleweed, Fedora, but you know what distribution wasn’t affected? Debian stable and Ubuntu LTS.

        And on top of that, I’m not even going to mention how unstable it is and how even just making updates is risky on Arch. You have to be on your toes all the time and you can end up with a broken system at any time. For a main PC operating system, I find that absolutely unacceptable. At least Manjaro tried to improve on this.

        Valve switching to Arch makes sense though. They moved to Arch because they wanted the most up to date software and drivers available with a faster release cycle. Then control what versions they push to their devices. They keep a tight control over what gets updated by curating their own repositories. So it’s not purely Arch either. It’s Arch-based. You can expect software to be a little older on Steam OS.

        In any case. For me, Debian is the solution. I’m looking for stability and security. It has a huge repo with practically every software under the sun. There’s tons of documentation and support and a huge community. For me the distribution works OOTB without any hitch. I just know that I won’t spend time troubleshooting something on my time off. I already do a lot of this during work.