astra-music-git

maintainer TheElevatedOne · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The npx command runs electron-builder on the project's own built source, which is a standard part of the build process for Electron apps and does not execute arbitrary remote code.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx command runs electron-builder on the project's own built source, which is a standard part of the build process for Electron apps and does not execute arbitrary remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:52 npx electron-builder --linux --dir

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Adam Mlady <adam.mlady@elevated.ovh>
2
3pkgname="astra-music-git"
4pkgdesc="Audiophile music player with advanced visualization"
5pkgrel=1
6pkgver=v0.6.1_beta_r249_gb95432e
7
8url="https://github.com/Boof2015/astra"
9arch=('x86_64')
10license=('GPL-3.0-only')
11provides=('astra')
12conflicts=('astra')
13makedepends=('npm' 'python' 'alsa-lib' 'git')
14options=('!strip' '!debug')
15source=("git+$url.git")
16md5sums=('SKIP')
17
18pkgver() {
19 cd "${srcdir}/astra"
20 git describe --tags --long --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/_/g'
21}
22
23prepare() {
24 cd "${srcdir}/astra"
25
26 if [[ -v ASTRA_LASTFM_KEY ]] && [[ -v ASTRA_LASTFM_SECRET ]]; then
27 cat >"${srcdir}/astra/.env.local" <<EOF
28LASTFM_API_KEY=${ASTRA_LASTFM_KEY}
29LASTFM_SHARED_SECRET=${ASTRA_LASTFM_SECRET}
30EOF
31 echo -e "\n[\033[1;32mINFO\033[0m] LastFM API Key and Secret Set\n"
32 fi
33
34 npm install
35
36 cat >"${srcdir}/astra.desktop" <<EOF
37[Desktop Entry]
38Name=Astra
39Comment=Audiophile music player with advanced visualization
40Exec=/opt/astra/astra %U
41Icon=astra
42Type=Application
43Categories=Audio;
44Terminal=false
45StartupWMClass=astra
46EOF
47}
48
49build() {
50 cd "${srcdir}/astra"
51 npm run build
52 npx electron-builder --linux --dir
53}
54
55package() {
56 _basedir="${srcdir}/astra"
57
58 install -Dm644 "${_basedir}/LICENSE" "${pkgdir}/usr/share/licenses/astra/LICENSE"
59
60 install -d "${pkgdir}/opt/astra"
61 cp -r "${_basedir}/dist/linux-unpacked/"* "${pkgdir}/opt/astra/"
62
63 install -Dm644 "${_basedir}/assets/logo/astra-logo-static.svg" "${pkgdir}/usr/share/icons/hicolor/scalable/apps/astra.svg"
64
65 install -Dm644 "${srcdir}/astra.desktop" "${pkgdir}/usr/share/applications/astra.desktop"
66}
67

Changes since previous scan

--- PKGBUILD @ 2026-07-29 00:25
+++ PKGBUILD @ 2026-08-03 00:08
@@ -3,7 +3,7 @@
pkgname="astra-music-git"
pkgdesc="Audiophile music player with advanced visualization"
pkgrel=1
-pkgver=v0.6.1_beta_r247_g00b0613
+pkgver=v0.6.1_beta_r249_gb95432e
url="https://github.com/Boof2015/astra"
arch=('x86_64')

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 23:13:22 MEDIUM 1
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 23:36:42 MEDIUM 1
2026-07-27 00:24:32 LOW 2
2026-07-26 19:33:02 MEDIUM 1
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 23:28:32 MEDIUM 1
2026-07-24 00:02:28 LOW 2
2026-07-23 23:26:18 MEDIUM 1
2026-07-23 00:14:47 LOW 2
2026-07-22 23:22:13 MEDIUM 1
2026-07-22 00:29:32 LOW 2
2026-07-21 23:18:24 MEDIUM 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion