bettbox-compatible-pre-bin

MEDIUM
maintainer VillagerTom 0 votes scanned 2026-09-29 05:22:53.434583
View on AUR
Why flagged

The package downloads a prebuilt .deb binary from a GitHub release of a project with few votes and recent upload, which is unpacked and installed without access to the source code for review, creating a supply-chain risk if the binary is compromised.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 90%): The package downloads a prebuilt .deb binary from a GitHub release of a project with few votes and recent upload, which is unpacked and installed without access to the source code for review, creating a supply-chain risk if the binary is compromised.

PKGBUILD

1# Maintainer: VillagerTom <villager-tom at proton dot me>
2
3pkgname=bettbox-compatible-pre-bin
4_pkgname=Bettbox
5pkgver=1.19.4pre1
6pkgrel=1
7_pkgver="${pkgver/pre/-pre}"
8pkgdesc="A multi-platform proxy client powered by the Mihomo (Clash Meta) core, refactored based on early versions of FlClash. (Build with GOAMD64=v1)"
9arch=('x86_64')
10url="https://github.com/appshubcc/Bettbox"
11license=('GPL-3.0-or-later')
12conflicts=('bettbox' 'bettbox-pre' 'bettbox-compatible' 'bettbox-compatible-pre' 'bettbox-compatible-bin' 'bettbox-bin')
13provides=("${pkgname%-compatible-pre-bin}=${pkgver}")
14depends=(
15 'gtk3'
16 'libayatana-appindicator'
17 'libkeybinder3'
18)
19optdepends=('polkit: for TUN authorization')
20options=('!debug')
21source=("restart-bettbox.hook")
22source_x86_64=(
23 "${pkgname%-pre-bin}-${pkgver}-${arch}.deb::${url}/releases/download/v${_pkgver}/${_pkgname}-${_pkgver%-pre*}-linux-amd64-compatible.deb"
24)
25sha256sums=('03d4aadb32c7a3876ac3dbafeb3d2ecd38b0fc87d19ff57d5dc46d452fd026a2')
26sha256sums_x86_64=('62cc81b9cebbfe175c99e2471a9264dbc77d8e885527aaed7b836b0ecd350267')
27
28prepare() {
29 bsdtar -xf "${srcdir}/data."*
30 sed -i -e "
31 s/Exec=${_pkgname}/Exec=${pkgname%-compatible-pre-bin}/g
32 s/Icon=${_pkgname}/Icon=${pkgname%-compatible-pre-bin}/g
33 5i\Categories=Network;
34 10i\StartupWMClass=com.appshub.bettbox
35 " "${srcdir}/usr/share/applications/${_pkgname}.desktop"
36}
37
38package() {
39 install -Dm755 -d "${pkgdir}/usr/bin"
40 ln -s "/usr/lib/${pkgname%-compatible-pre-bin}/${_pkgname}" "${pkgdir}/usr/bin/${pkgname%-compatible-pre-bin}"
41 install -Dm755 -d "${pkgdir}/usr/lib/${pkgname%-compatible-pre-bin}"
42 cp -Pr --no-preserve=ownership "${srcdir}/usr/share/${_pkgname}/"* "${pkgdir}/usr/lib/${pkgname%-compatible-pre-bin}/"
43 install -Dm644 "${srcdir}/usr/share/applications/${_pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname%-compatible-pre-bin}.desktop"
44 install -Dm644 "${srcdir}/usr/share/icons/hicolor/128x128/apps/${_pkgname}.png" "${pkgdir}/usr/share/icons/hicolor/128x128/apps/${pkgname%-compatible-pre-bin}.png"
45 install -Dm644 "${srcdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png" "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${pkgname%-compatible-pre-bin}.png"
46
47 install -Dm644 -t "${pkgdir}/usr/share/libalpm/hooks/" "${srcdir}/restart-bettbox.hook"
48
49 # Set setuid on BettboxCore for TUN mode (to avoid password prompt)
50 chmod u+sx "${pkgdir}/usr/lib/${pkgname%-compatible-pre-bin}/BettboxCore"
51}
52

Scan history

Scanned at (UTC)SeverityRules
2026-09-29 05:22:53 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion