bettbox-pre-bin

MEDIUM
maintainer VillagerTom 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package downloads prebuilt .deb binaries from a GitHub release on a non-whitelisted host (GitHub is generally trusted but the project's ownership and build provenance are unclear due to low votes and recent upload), which are then unpacked and installed; this creates a supply-chain risk if the upstream binaries are compromised or malicious.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 95%): The package downloads prebuilt .deb binaries from a GitHub release on a non-whitelisted host (GitHub is generally trusted but the project's ownership and build provenance are unclear due to low votes and recent upload), which are then unpacked and installed; this creates a supply-chain risk if the upstream binaries are compromised or malicious.

PKGBUILD

1# Maintainer: VillagerTom <villager-tom at proton dot me>
2
3pkgname=bettbox-pre-bin
4_pkgname=Bettbox
5pkgver=1.19.4
6pkgrel=1
7_pkgver="${pkgver/pre/-pre}"
8pkgdesc="A multi-platform proxy client powered by the Mihomo (Clash Meta) core, refactored based on early versions of FlClash."
9arch=('x86_64' 'aarch64')
10url="https://github.com/appshubcc/${_pkgname}"
11license=('GPL-3.0-or-later')
12conflicts=('bettbox' 'bettbox-compatible' 'bettbox-compatible-pre' 'bettbox-compatible-bin' 'bettbox-bin' 'bettbox-pre' 'bettbox-compatible-pre-bin')
13provides=("${pkgname%-pre-bin}=${pkgver}")
14depends=(
15 'gtk3'
16 'libayatana-appindicator'
17 'libkeybinder3'
18)
19optdepends=('polkit: for TUN authorization')
20options=('!debug')
21source=("restart-bettbox.hook")
22# Upstream names its debs by Debian architecture (amd64/arm64), which does not
23# match the AUR architecture names, so both the cache name and the URL are
24# spelled out per architecture. ${arch} cannot be used here: makepkg binds it
25# to the *host* architecture while expanding per-arch arrays, so it would give
26# both entries the same cache name.
27source_x86_64=(
28 "${pkgname%-pre-bin}-${pkgver}-x86_64.deb::${url}/releases/download/v${_pkgver}/${_pkgname}-${_pkgver%-pre*}-linux-amd64.deb"
29)
30source_aarch64=(
31 "${pkgname%-pre-bin}-${pkgver}-aarch64.deb::${url}/releases/download/v${_pkgver}/${_pkgname}-${_pkgver%-pre*}-linux-arm64.deb"
32)
33sha256sums=('03d4aadb32c7a3876ac3dbafeb3d2ecd38b0fc87d19ff57d5dc46d452fd026a2')
34sha256sums_x86_64=('5e9133e3fd6249ae09b26a93051075dc82fa6b7255ce1a7c14b43113e7effc80')
35sha256sums_aarch64=('4422a41e8456647ecbe3d7ab07e7c763f899f3208eb79007a419b53f180bdc40')
36
37prepare() {
38 bsdtar -xf "${srcdir}/data."*
39 # Upstream already ships Categories=Network; (line 8), so only the missing
40 # StartupWMClass is inserted, right before StartupNotify=true (line 10).
41 sed -i -e "
42 s/Exec=${_pkgname}/Exec=${pkgname%-pre-bin}/g
43 s/Icon=${_pkgname}/Icon=${pkgname%-pre-bin}/g
44 10i\StartupWMClass=com.appshub.bettbox
45 " "${srcdir}/usr/share/applications/${_pkgname}.desktop"
46}
47
48package() {
49 install -Dm755 -d "${pkgdir}/usr/bin"
50 ln -s "/usr/lib/${pkgname%-pre-bin}/${_pkgname}" "${pkgdir}/usr/bin/${pkgname%-pre-bin}"
51 install -Dm755 -d "${pkgdir}/usr/lib/${pkgname%-pre-bin}"
52 cp -Pr --no-preserve=ownership "${srcdir}/usr/share/${_pkgname}/"* "${pkgdir}/usr/lib/${pkgname%-pre-bin}/"
53 install -Dm644 "${srcdir}/usr/share/applications/${_pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname%-pre-bin}.desktop"
54 install -Dm644 "${srcdir}/usr/share/icons/hicolor/128x128/apps/${_pkgname}.png" "${pkgdir}/usr/share/icons/hicolor/128x128/apps/${pkgname%-pre-bin}.png"
55 install -Dm644 "${srcdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png" "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${pkgname%-pre-bin}.png"
56
57 install -Dm644 -t "${pkgdir}/usr/share/libalpm/hooks/" "${srcdir}/restart-bettbox.hook"
58
59 # Set setuid on BettboxCore for TUN mode (to avoid password prompt)
60 chmod u+sx "${pkgdir}/usr/lib/${pkgname%-pre-bin}/BettboxCore"
61}
62

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Medium 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion