

It’s no arch fuckup. The AUR is not an arch linux redponsibility and has always been “untrusted” - you should always verify what you’re downloading and building.
Problem is that bazzite and cachy are arch-based, but targeted at a group of people that arch doesn’t target. So you have users that just blindly download scripts from the AUR without doing proper verification.
This is more the fault of those distros and AUR helpers than arch.





A single ship? Ye, no impact.
Thousands? Well, that will be very noticeable.