astra-music-git
maintainer TheElevatedOne
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The npx command runs electron-builder on the project's own built source, which is a standard part of the build process for Electron apps and does not execute arbitrary remote code.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx command runs electron-builder on the project's own built source, which is a standard part of the build process for Electron apps and does not execute arbitrary remote code.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
npx/bunx/deno executes a remote package
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:52
npx electron-builder --linux --dir
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Adam Mlady <adam.mlady@elevated.ovh>
2
3
pkgname="astra-music-git"
4
pkgdesc="Audiophile music player with advanced visualization"
5
pkgrel=1
6
pkgver=v0.6.1_beta_r249_gb95432e
7
8
url="https://github.com/Boof2015/astra"
9
arch=('x86_64')
10
license=('GPL-3.0-only')
11
provides=('astra')
12
conflicts=('astra')
13
makedepends=('npm' 'python' 'alsa-lib' 'git')
14
options=('!strip' '!debug')
15
source=("git+$url.git")
16
md5sums=('SKIP')
17
18
pkgver() {
19
cd "${srcdir}/astra"
20
git describe --tags --long --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/_/g'
21
}
22
23
prepare() {
24
cd "${srcdir}/astra"
25
26
if [[ -v ASTRA_LASTFM_KEY ]] && [[ -v ASTRA_LASTFM_SECRET ]]; then
27
cat >"${srcdir}/astra/.env.local" <<EOF
28
LASTFM_API_KEY=${ASTRA_LASTFM_KEY}
29
LASTFM_SHARED_SECRET=${ASTRA_LASTFM_SECRET}
30
EOF
31
echo -e "\n[\033[1;32mINFO\033[0m] LastFM API Key and Secret Set\n"
32
fi
33
34
npm install
35
36
cat >"${srcdir}/astra.desktop" <<EOF
37
[Desktop Entry]
38
Name=Astra
39
Comment=Audiophile music player with advanced visualization
40
Exec=/opt/astra/astra %U
41
Icon=astra
42
Type=Application
43
Categories=Audio;
44
Terminal=false
45
StartupWMClass=astra
46
EOF
47
}
48
49
build() {
50
cd "${srcdir}/astra"
51
npm run build
52
npx electron-builder --linux --dir
53
}
54
55
package() {
56
_basedir="${srcdir}/astra"
57
58
install -Dm644 "${_basedir}/LICENSE" "${pkgdir}/usr/share/licenses/astra/LICENSE"
59
60
install -d "${pkgdir}/opt/astra"
61
cp -r "${_basedir}/dist/linux-unpacked/"* "${pkgdir}/opt/astra/"
62
63
install -Dm644 "${_basedir}/assets/logo/astra-logo-static.svg" "${pkgdir}/usr/share/icons/hicolor/scalable/apps/astra.svg"
64
65
install -Dm644 "${srcdir}/astra.desktop" "${pkgdir}/usr/share/applications/astra.desktop"
66
}
67
Changes since previous scan
--- PKGBUILD @ 2026-07-29 00:25+++ PKGBUILD @ 2026-08-03 00:08@@ -3,7 +3,7 @@ pkgname="astra-music-git" pkgdesc="Audiophile music player with advanced visualization" pkgrel=1-pkgver=v0.6.1_beta_r247_g00b0613+pkgver=v0.6.1_beta_r249_gb95432e url="https://github.com/Boof2015/astra" arch=('x86_64')Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 23:13:22 | MEDIUM | 1 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 23:36:42 | MEDIUM | 1 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 19:33:02 | MEDIUM | 1 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 23:28:32 | MEDIUM | 1 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 23:26:18 | MEDIUM | 1 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 23:22:13 | MEDIUM | 1 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 23:18:24 | MEDIUM | 1 |