[Proposal] Securing orphaned AUR packages and maintainer voting
Fellow Archers, Freedom of choice is our greatest strength. With that in mind, I would like to propose a solution regarding the recent AUR issues. My first proposal is to establish a public, read-only "orphanage" repository for orphaned packages. Only active maintainers with a proven reputation would be permitted to adopt packages from this repository. This would require a ranking or voting system for maintainers, potentially similar to the existing AUR voting mechanism. Adoption requests from the general public could then be processed via community voting or other established channels, such as the official forums. The second proposal is to automatically lock all orphaned packages from public modification. Upon adoption, the new maintainer would need to request an unlock from active maintainers. As with the first proposal, public adoption requests would be handled through voting or forum channels. I believe this is a straightforward, elegant, and secure approach for our community. I hope the Board will consider this proposal. Kind regards, Aleksandar Zarić - salexandarz
I support tippfehlr's suggestion: https://gitlab.archlinux.org/archlinux/aurweb/-/work_items/558 Perhaps we could start with less drastic measures, such as creating a way to submit a report quickly and easily, so that next time there won’t be long delays when the first signs of an attack appear, because there were such signs, and we first had to figure out how and where to address them. I know I'm repeating myself, but why not try it this way first: https://gitlab.archlinux.org/archlinux/aurweb/-/work_items/558 You can't save freedom by over-bureaucratizing it through knee-jerk reactions!
participants (2)
-
Aleksandar Zarić
-
Ralf Mardorf