i started using Chaotic-AUR on one of my machines, because it is convenient.
It provides a lot of prebuilt packages.
Do someone know if this repo is safe?
Or how to find out?
Chaotic-AUR automated building repo for AUR packages
https://aur.chaotic.cx/
Generally speaking, if you worry about safety it is better to build programs from source. Even then, you can't be sure if it is safe if you don't spend the time to check the source code or don't trust the distributor.
With AUR in general, "anything goes". That's why it is not officially supported. There are rally nasty packages in AUR, made as a "proof of concept", which can gain root access if the user just skips inspecting the PKGBUILD by just mechanically pressing Enter.
What
@strajder said. I could use chaotic-aur or archlinuxcn unofficial repos for my grandmother's Artix, but not for the PC I store my gpg and ssh keys on.
Huh... you are not very nice to your grandma
@nous and you understimate grandmas I think :D ;)
LOL, grandma is supposed to sit in front of a desktop like this.
(https://i.redd.it/emp4516xfwq71.jpg)
It should be proper retro green.
Okay, I can see that...
asking the question is answering it already :D
This reminds me one thing:
Is there a similar tool like debsums in Arch?
it checks the MD5 sums of installed Debian packages, tells you altered or missing files from the original packages.
Answering to myself:
$ sudo pacman -Qk |grep -v "0 missing files"
warning: artix-branding-base: /etc/local.d/0PS1.start (No such file or directory)
warning: artix-branding-base: /etc/local.d/mkinitcpio.start (No such file or directory)
artix-branding-base: 18 total files, 2 missing files
warning: kgpg: /etc/xdg/autostart/org.kde.kgpg.desktop (No such file or directory)
kgpg: 381 total files, 1 missing file
warning: wps-office: /usr/lib/office6/wpscloudsvr (No such file or directory)
wps-office: 3900 total files, 1 missing file
What are the warnings in "warning: artix-branding-base"??
wpscloudsvr is a local server launched by WPS office suite. I deleted it
Btw now I switched to Onlyoffice which is good enough for my usage.
Caught grandma sniffing our home LAN. :o