bettbox-pre-bin
The package downloads prebuilt .deb binaries from a GitHub release on a non-whitelisted host (GitHub is generally trusted but the project's ownership and build provenance are unclear due to low votes and recent upload), which are then unpacked and installed; this creates a supply-chain risk if the upstream binaries are compromised or malicious.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 95%): The package downloads prebuilt .deb binaries from a GitHub release on a non-whitelisted host (GitHub is generally trusted but the project's ownership and build provenance are unclear due to low votes and recent upload), which are then unpacked and installed; this creates a supply-chain risk if the upstream binaries are compromised or malicious.
PKGBUILD
# Maintainer: VillagerTom <villager-tom at proton dot me>
pkgname=bettbox-pre-bin
_pkgname=Bettbox
pkgver=1.19.4
pkgrel=1
_pkgver="${pkgver/pre/-pre}"
pkgdesc="A multi-platform proxy client powered by the Mihomo (Clash Meta) core, refactored based on early versions of FlClash."
arch=('x86_64' 'aarch64')
url="https://github.com/appshubcc/${_pkgname}"
license=('GPL-3.0-or-later')
conflicts=('bettbox' 'bettbox-compatible' 'bettbox-compatible-pre' 'bettbox-compatible-bin' 'bettbox-bin' 'bettbox-pre' 'bettbox-compatible-pre-bin')
provides=("${pkgname%-pre-bin}=${pkgver}")
depends=(
'gtk3'
'libayatana-appindicator'
'libkeybinder3'
)
optdepends=('polkit: for TUN authorization')
options=('!debug')
source=("restart-bettbox.hook")
# Upstream names its debs by Debian architecture (amd64/arm64), which does not
# match the AUR architecture names, so both the cache name and the URL are
# spelled out per architecture. ${arch} cannot be used here: makepkg binds it
# to the *host* architecture while expanding per-arch arrays, so it would give
# both entries the same cache name.
source_x86_64=(
"${pkgname%-pre-bin}-${pkgver}-x86_64.deb::${url}/releases/download/v${_pkgver}/${_pkgname}-${_pkgver%-pre*}-linux-amd64.deb"
)
source_aarch64=(
"${pkgname%-pre-bin}-${pkgver}-aarch64.deb::${url}/releases/download/v${_pkgver}/${_pkgname}-${_pkgver%-pre*}-linux-arm64.deb"
)
sha256sums=('03d4aadb32c7a3876ac3dbafeb3d2ecd38b0fc87d19ff57d5dc46d452fd026a2')
sha256sums_x86_64=('5e9133e3fd6249ae09b26a93051075dc82fa6b7255ce1a7c14b43113e7effc80')
sha256sums_aarch64=('4422a41e8456647ecbe3d7ab07e7c763f899f3208eb79007a419b53f180bdc40')
prepare() {
bsdtar -xf "${srcdir}/data."*
# Upstream already ships Categories=Network; (line 8), so only the missing
# StartupWMClass is inserted, right before StartupNotify=true (line 10).
sed -i -e "
s/Exec=${_pkgname}/Exec=${pkgname%-pre-bin}/g
s/Icon=${_pkgname}/Icon=${pkgname%-pre-bin}/g
10i\StartupWMClass=com.appshub.bettbox
" "${srcdir}/usr/share/applications/${_pkgname}.desktop"
}
package() {
install -Dm755 -d "${pkgdir}/usr/bin"
ln -s "/usr/lib/${pkgname%-pre-bin}/${_pkgname}" "${pkgdir}/usr/bin/${pkgname%-pre-bin}"
install -Dm755 -d "${pkgdir}/usr/lib/${pkgname%-pre-bin}"
cp -Pr --no-preserve=ownership "${srcdir}/usr/share/${_pkgname}/"* "${pkgdir}/usr/lib/${pkgname%-pre-bin}/"
install -Dm644 "${srcdir}/usr/share/applications/${_pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname%-pre-bin}.desktop"
install -Dm644 "${srcdir}/usr/share/icons/hicolor/128x128/apps/${_pkgname}.png" "${pkgdir}/usr/share/icons/hicolor/128x128/apps/${pkgname%-pre-bin}.png"
install -Dm644 "${srcdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png" "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${pkgname%-pre-bin}.png"
install -Dm644 -t "${pkgdir}/usr/share/libalpm/hooks/" "${srcdir}/restart-bettbox.hook"
# Set setuid on BettboxCore for TUN mode (to avoid password prompt)
chmod u+sx "${pkgdir}/usr/lib/${pkgname%-pre-bin}/BettboxCore"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:13:36 | Medium | 2 |
| 2026-10-05 23:40:58 | Low | 1 |