Three dominant themes from the discussion
- AUR’s supply‑chain trust model is fundamentally insecure – the ability to adopt orphaned packages lets attackers push malicious updates, and many users note that this risk can’t be patched without removing the feature.
- al_9des_RAWR2: "I assumed the goal was to reduce usage of AUR, they've actually remove the ability to adopt (take ownership of) orphaned packages."
- OJFord: "It's simply volunteering to maintain the package after previous maintainer(s) have explicitly disowned it..."
-
ameliaquining: "The security problems with unilateral adoption of orphaned packages by unprivileged users are fundamental and unfixable; the only remedy is to remove the feature."
-
Disabling package adoption is viewed as a necessary but temporary stop‑gap – commenters emphasize that the shutdown exposes the AUR’s fragile security and that it feels like a stop‑gap measure rather than a sustainable solution.
- uticus: "From the actual announcement: ...package adoption is currently disabled while we are handling the situation."
- pessimizer: "Sounds like it has been disabled, which is exactly what was said."
-
Matl: "Well, this kills a very useful feature of the AUR. It's like Wikipedia disabling editing."
-
The myth of “honor among hackers” is eroding – long‑standing expectations of trust are giving way to concerns that the open, anonymous nature of the AUR is now attracting malicious actors, especially with AI‑generated scripts.
- Sleaker: "I don't think any form of automated adoption of orphaned packages will ever work, it's just too easy to introduce malicious code into an otherwise functional but no longer maintained source."
- charcircuit: "Desktop Linux has always been a house of cards in regards to security... this was inevitable."
- jolmg: "Arch is simply getting popular enough to be targeted."