While that is true what concerned me most was the intial post being this instead of an into tbh, very easy to make a program seem innocent then change the code (not accusing you of this but also why I am very caustios of it as the long game often pays off more when hacking something - again just my paranoia ho[e you prove it wrong)
honestly I probably should have explained the background of NeoArch better in my original post.
NeoArch actually started in 2024 as my university final project. I wanted to choose a real problem rather than build something just for an assignment. Before NeoArch, I had already made smaller scripts and tools for managing AUR/packages, including one called Aurora. Over time I kept thinking that I could make something more useful and complete.
I had around 13 years of experience using Windows and macOS before moving to Linux. I tried Fedora and eventually moved to Arch because I wanted to understand Linux more deeply. In my daily use of Arch, I sometimes wanted a good GUI option for certain tasks, similar to the convenience people have on Windows or macOS, while still keeping the transparency and control that Arch provides. That was one of the reasons I started experimenting with this idea.
NeoArch has grown a lot since the original university project, and V3 is the result of continuing that work rather than something I created recently.
I also want to be clear that I’m not trying to make money from NeoArch. I already have a job, and the project is something I work on because I enjoy development, Linux, and open source. I have a small sponsorship/Buy Me a Coffee option, but any support isn’t something I depend on personally. One of my long-term goals is to use whatever I can contribute from my work to help students who have fewer opportunities. I’ve had some difficult paths myself, so that matters to me.
My background is also publicly available, and I’m happy to be accountable for the project and its code. I’m not asking anyone to blindly trust NeoArch. If you’re cautious, please inspect the code, test it, and tell me where you think something could be improved.
I appreciate you being cautious rather than simply assuming everything is fine. I’ll take that as motivation to be more transparent about the project and its development.
yer while I still won’t use and code is open, I still can’t trust due to the way it was intoduced (forum first post, just suss to me) I will not say more as others can see and make their own judgment and as I also said I hope you prove my distrust wrong (still not for me then but yer). Sorry if I aint making too much sense had a real hard day today and still tying it up. But long story short wish you well and all the best with your learing - head to tired for more.
I understand where you’re coming from, especially if the way the project was introduced gave you a bad feeling. No worries, and I appreciate you taking the time to explain it, especially after a hard day.
Just for context, I’m an Arch user myself, and I develop websites, mobile and desktop applications, as well as doing DevOps work. NeoArch started as a university project in 2024 and has grown through a lot of testing and iteration since then. I’m not asking anyone to blindly trust me — the code is open and people can inspect it and make their own judgment.
And if there’s any particular concern beyond the project itself, feel free to say so. If it’s something private or personal that you’d rather not share, that’s completely fine too. I hope over time the project itself can prove whether it deserves trust. Thanks again, and I wish you a better day.
This is sort of where I also have caution can’t really explain it but something off in they way you respind so quick, especially as you mentioned this aint ya tongue, just something not right and I stick with gut
suprise, suprise 0 response again on similar comment. 0 trust fom me and suspect this github account comprimised - could be wrong but gut says nah man. Anyway i off to get some dinner.
No worries, I understand. If your gut tells you not to trust the account/project, I respect that. I’m not going to try to force you to change your mind. The GitHub repo is public, so anyone can inspect the code and history and make their own judgment.
Anyway, enjoy your dinner, and thanks for taking the time to explain your concerns. All the best.
Just to clarify one thing, Sinhala is my first language and English is my second. I use Grammarly sometimes to help correct my grammar, so that may also explain why some of my replies can look a bit different or polished.
What part of a USER should NEVER do a PARTIAL upgrade did you not understand?
What if you’ve locked a package because it breaks?
do it manually that should at least show the USER understands what they are doing.
I figured it out for me what is off, an agent always almost responds this way. Sorry if you not butbyerbi leaving this thread.
Ie agrees then talk shite that backs up question
But the project, code, testing, and maintenance are mine.Anyway, I respect your decision to leave the thread. Thanks for being honest about your concerns, and all the best.
Sure, that’s the best way. But if you are using a GUI workflow, it should at least entertain the possibility.
@sanjaya that’s another new feature (if it doesn’t already have it)
Yeah, if you lock a package because a newer version breaks something, NeoArch respects that and won’t upgrade it. You can un-ignore/un-hold it later from the package menu or settings.
If the newer version is the problem, you can also downgrade to a cached version and pin it so pacman doesn’t pull the broken version again.
One thing I haven’t handled yet is automatically reminding you that a pinned package is still outdated. That’s probably something worth improving.
Yeah, I get your point. The current behavior was meant as a temporary solution, but I agree this could be handled better. I’ll add it to my todo list and look at changing the update flow so partial system upgrades aren’t encouraged.
I should be able to work on this over the next week or two.
for now i need to time forI didn’t remove partial upgrades because that would be wrong and impossible. Full removal is unimplementable (single-package updates are legitimate — e.g. updating just one tool needs pacman -S and Arch itself allows it), and hard-blocking would drive power users to the terminal where we lose all control. Instead, per the code docstring, the goal was to make silent accidental partial upgrades impossible: the user now must explicitly click “I understand — Update Selection”. The security page confirms this policy is intentional — the chip literally reads “Warned, not blocked”.
Any questions? I have plenty of time to respond right now. I’m on vacation these days. That gives me more time to think, check your ideas, and go through my code. So yeah, the quick replies are mostly because I actually have the time right now
.so in my life I’m staying off social media and using my phone less. this is my daily mobile usage .
Is your intention to put this package in the Arch AUR? Or just have a github link?
