The past few times I’ve run yay I’ve got these warnings about packages that are orphaned/not in the AUR. Based on the names I’m assuming these are leftover from the upgrade from kde plasma 5 to 6, are these safe to remove now? And secondly how would I find orphaned packages like that if I wasn’t using yay since I never installed these from the AUR?

  • OneCardboardBox@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    8 months ago

    In this context, orphaned doesn’t always mean you should remove it. It just means that nobody in AUR is taking responsibility to keep it updated. You still might have other packages from the AUR that depend on this one.

    Since it is unmaintained, basically anyone can now claim ownership of that package in the AUR and push updates for it. Theoretically, someone could try to distribute malware in this way.

    This is why it’s important to check the diffs of your AUR updates.