airwallex-cli

LOW
maintainer orphaned 1 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package builds from official upstream release assets with proper checksum verification via an upstream-provided integrity file; the only concern is the restrictive EULA disallowing redistribution, but the source and build process are transparent and safe.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from official upstream release assets with proper checksum verification via an upstream-provided integrity file; the only concern is the restrictive EULA disallowing redistribution, but the source and build process are transparent and safe.

PKGBUILD

1# Maintainer: enihcam <enihcam@archlinux>
2
3# Upstream ships no LICENSE file; the "Important Notice" in the README is the
4# sole license grant. It explicitly disallows redistribution, modification, and
5# reverse-engineering, which is unusual for AUR but the tarballs themselves are
6# publicly downloadable. See PKGBUILD comments and package() before redistributing.
7
8pkgname=airwallex-cli
9pkgver=0.4.1
10pkgrel=1
11pkgdesc='CLI for the Airwallex platform (proprietary beta)'
12arch=('x86_64' 'aarch64')
13url='https://github.com/airwallex/airwallex-cli'
14license=('LicenseRef-Airwallex-CLI-EULA')
15depends=('glibc')
16optdepends=('bash-completion: shell completions (provided by upstream)')
17provides=('airwallex')
18conflicts=('airwallex')
19
20# Per-OS upstream checksum file is the same artifact the official install.sh
21# downloads for integrity verification. We use it to pin both per-arch tarball
22# digests so makepkg refuses to package a tampered asset, and then ship it
23# under /usr/share so users can reproduce the check out-of-band.
24source=(
25 "airwallex-linux-checksums.txt::https://github.com/airwallex/airwallex-cli/releases/download/v${pkgver}/airwallex-linux-checksums.txt"
26 "LICENSE::https://raw.githubusercontent.com/airwallex/airwallex-cli/master/README.md"
27)
28
29# amd64 / arm64 sha256 digests cross-checked against the upstream
30# airwallex-linux-checksums.txt on 2026-09-30; do NOT edit these by hand.
31sha256sums=(
32 'ec95d740f44368511db0cc4cdeaf945f38ff0e52f3227c5f31c9f7602a098b2d' # airwallex-linux-checksums.txt
33 'SKIP' # README.md license notice
34)
35
36# CARCH -> asset filename fragment used by upstream release artifacts.
37_asset_for_carch() {
38 case "$CARCH" in
39 x86_64) echo 'amd64' ;;
40 aarch64) echo 'arm64' ;;
41 *) return 1 ;;
42 esac
43}
44
45prepare() {
46 local asset="airwallex_${pkgver}_linux_$(_asset_for_carch).tar.gz"
47 local url="https://github.com/airwallex/airwallex-cli/releases/download/v${pkgver}/${asset}"
48
49 msg2 "Downloading ${asset}"
50 if ! curl -fsSL -o "${srcdir}/${asset}" "${url}"; then
51 error "Failed to download ${url}"
52 return 1
53 fi
54
55 # Use the upstream-issued per-OS checksums file (the same one the official
56 # install.sh consumes) to verify the downloaded archive before extraction.
57 local expected
58 expected=$(awk -v name="$asset" '$2 == name { print $1; exit }' \
59 "$srcdir/airwallex-linux-checksums.txt")
60 if [ -z "$expected" ]; then
61 error "Asset ${asset} not listed in airwallex-linux-checksums.txt"
62 return 1
63 fi
64
65 local actual
66 actual=$(sha256sum "$srcdir/$asset" | awk '{print $1}')
67 if [ "$expected" != "$actual" ]; then
68 error "SHA256 mismatch for ${asset}: expected ${expected}, got ${actual}"
69 return 1
70 fi
71 msg2 "Checksum OK (${actual})"
72}
73
74package() {
75 local asset="airwallex_${pkgver}_linux_$(_asset_for_carch).tar.gz"
76
77 install -d "$pkgdir/usr/bin"
78
79 # Tarball layout: a single `airwallex` executable at the archive root.
80 bsdtar --no-same-owner -xf "$srcdir/$asset" -C "$pkgdir/usr/bin" airwallex
81 chmod 0755 "$pkgdir/usr/bin/airwallex"
82
83 # Ship the upstream notice + integrity artifacts under /usr/share so users
84 # can read the EULA terms and re-verify against the published checksums
85 # without going back to GitHub.
86 install -Dm0644 "$srcdir/LICENSE" \
87 "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
88 install -Dm0644 "$srcdir/airwallex-linux-checksums.txt" \
89 "$pkgdir/usr/share/licenses/$pkgname/airwallex-linux-checksums.txt"
90}
91

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion