astra-music-git

LOW
maintainer TheElevatedOne 1 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The npx command runs electron-builder on the locally built project, which is a standard part of the build process for Electron apps and does not execute untrusted remote code.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx command runs electron-builder on the locally built project, which is a standard part of the build process for Electron apps and does not execute untrusted remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:52 npx electron-builder --linux --dir

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Adam Mlady <adam.mlady@elevated.ovh>
2
3pkgname="astra-music-git"
4pkgdesc="Audiophile music player with advanced visualization"
5pkgrel=1
6pkgver=v0.7.0_beta_r69_g1e42443
7
8url="https://github.com/Boof2015/astra"
9arch=('x86_64')
10license=('GPL-3.0-only')
11provides=('astra')
12conflicts=('astra')
13makedepends=('npm' 'python' 'alsa-lib' 'git')
14options=('!strip' '!debug')
15source=("git+$url.git")
16md5sums=('SKIP')
17
18pkgver() {
19 cd "${srcdir}/astra"
20 git describe --tags --long --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/_/g'
21}
22
23prepare() {
24 cd "${srcdir}/astra"
25
26 if [[ -v ASTRA_LASTFM_KEY ]] && [[ -v ASTRA_LASTFM_SECRET ]]; then
27 cat >"${srcdir}/astra/.env.local" <<EOF
28LASTFM_API_KEY=${ASTRA_LASTFM_KEY}
29LASTFM_SHARED_SECRET=${ASTRA_LASTFM_SECRET}
30EOF
31 echo -e "\n[\033[1;32mINFO\033[0m] LastFM API Key and Secret Set\n"
32 fi
33
34 npm install
35
36 cat >"${srcdir}/astra.desktop" <<EOF
37[Desktop Entry]
38Name=Astra
39Comment=Audiophile music player with advanced visualization
40Exec=/opt/astra/astra %U
41Icon=astra
42Type=Application
43Categories=Audio;
44Terminal=false
45StartupWMClass=astra
46EOF
47}
48
49build() {
50 cd "${srcdir}/astra"
51 npm run build
52 npx electron-builder --linux --dir
53}
54
55package() {
56 _basedir="${srcdir}/astra"
57
58 install -Dm644 "${_basedir}/LICENSE" "${pkgdir}/usr/share/licenses/astra/LICENSE"
59
60 install -d "${pkgdir}/opt/astra"
61 cp -r "${_basedir}/dist/linux-unpacked/"* "${pkgdir}/opt/astra/"
62
63 install -Dm644 "${_basedir}/assets/logo/astra-logo-static.svg" "${pkgdir}/usr/share/icons/hicolor/scalable/apps/astra.svg"
64
65 install -Dm644 "${srcdir}/astra.desktop" "${pkgdir}/usr/share/applications/astra.desktop"
66}
67

Changes since previous scan

--- PKGBUILD @ 2026-09-14 00:27
+++ PKGBUILD @ 2026-09-17 00:27
@@ -3,7 +3,7 @@
pkgname="astra-music-git"
pkgdesc="Audiophile music player with advanced visualization"
pkgrel=1
-pkgver=v0.7.0_beta_r60_gb85f8ef
+pkgver=v0.7.0_beta_r69_g1e42443
url="https://github.com/Boof2015/astra"
arch=('x86_64')

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 01:15:25 Medium 1
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 23:58:52 Medium 1
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 23:51:41 Medium 1
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion