I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.

    • pastermil@sh.itjust.works
      link
      fedilink
      arrow-up
      20
      ·
      2 months ago

      And even the blobs in the first point there are source and build instructions in their respective folder.

      No it is not. It is supposedly the built result based on the instruction provided. If they can just provide that instruction, why not provide the source as well?

      The issue thread also highlights the stubbornness and hostility of the project maintainer toward possible contributors.

    • thingsiplay@beehaw.org
      link
      fedilink
      arrow-up
      13
      ·
      2 months ago

      That linked reply doesn’t explain anything. It just says “bro trust him”. Just because you and the AUR maintainer says its trustful, does not make it clear whats behind the binary blobs. It doesn’t matter what anyone says, if we can’t verify. In my opinion, its absurd calling others absurd for not trusting the word of others.