• pbsds@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    edit-2
    14 hours ago

    Comparing the AUR to nixpkgs is like comparing the NUR and random flakes to the main Arch repositories.

    Had the AUR been prefixing the package names with the maintainer name like the NUR does, then it would not be possible to do the orphan adoption attack at the same scale. (Instead a bunch of duplicates with higher version numbers would pop up, prompting users to switch)