this post was submitted on 16 Jun 2023
7 points (100.0% liked)
Arch Linux
7777 readers
1 users here now
The beloved lightweight distro
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Hmm, that's a good point. Were you able to take over the existing package? With npm and some other self-publishing repos you can squat a name that hasn't been taken, but an existing package cannot be taken over without the original owner's credentials.
I had full control over the pkgbuild as soon as I uploaded an ssh key to my AUR account. I did end up pushing a small update that fixed a missing download link, but I could just have easily changed the download artifacts. I know that some AUR helper encourage users to check pkgbuild diffs, but I'm sure many (most) people skip that step.