>>106140557>even MacOS has Brewsh and Windows has ChocolateyThese aren't official, same way with external debian repos, aur is more or less a way to package shit by users that's integrated within the distro's package manager, it would be somewhat like fedora's copr, opensuse's obs or ubuntu's ppas.
And it's been always common knowledge that you shouldn't blindly trust some aur package because they're not "official" but anyone with an arch installation can upload them, so a hacker can upload them too there, the same way someone could upload malware to copr, ppa or obs.