Arch's AUR Belongs to the Past | Source Code Ep. 23

0:00 Intro 0:49 Trust vs Verification 1:35 What the AUR Actually Is 3:08 Atomic Arch The Incident 4:07 Inside the Payload 5:57 This Already Happened in 2018 7:04 A Model Built for Another Era 8:06 Guix and the Power to Verify 10:10 Not Hating Arch 10:46 Debian Adapted Arch Didn't 12:09 LibreOffice vs OnlyOffice 14:16 Firefox Goes All In 15:59 Firefox 152 and JPEG XL 16:34 Linux Kernel 7.1 18:07 Conclusion The AUR just suffered one of the worst supply chain attacks in its history, and it exposed a deeper truth: its trust model belongs to another era. This week we dig into Atomic Arch, the orphan adoption flaw behind it, and why reproducible builds and tools like guix challenge point to where the ecosystem is really heading. Plus the LibreOffice vs OnlyOffice format war, Firefox going all in with its free VPN, and Linux kernel 7.1. Trust is not security.