blinko-desktop-git

LOW
maintainer kanya-approve 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

The `bunx tauri build` command runs the project's own bundled tauri CLI (installed via `bun install --frozen-lockfile` from the project's lockfile) to compile the project's own source code from the official GitHub repo; this is normal build tooling, not fetching and executing an unrelated remote package. The SKIP'd checksums on local helper files (the .sh launcher and .desktop file) are sloppy but not dangerous, and the git source is from the official upstream repo.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The `bunx tauri build` command runs the project's own bundled tauri CLI (installed via `bun install --frozen-lockfile` from the project's lockfile) to compile the project's own source code from the official GitHub repo; this is normal build tooling, not fetching and executing an unrelated remote package. The SKIP'd checksums on local helper files (the .sh launcher and .desktop file) are sloppy but not dangerous, and the git source is from the official upstream repo.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:43 bunx tauri build --bundles appimage \

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Brian Kanya <briankanya@gmail.com>
2
3pkgname=blinko-desktop-git
4_pkgname=blinko
5pkgver=1.8.8.r2091.gb2586d03
6pkgrel=1
7pkgdesc='Blinko desktop client (AppImage built from git); connects to a self-hosted Blinko server'
8arch=('x86_64')
9url='https://github.com/blinkospace/blinko'
10license=('GPL-3.0-only')
11depends=('glibc')
12makedepends=('git' 'bun' 'rust' 'webkit2gtk-4.1' 'gtk3' 'librsvg' 'libayatana-appindicator'
13 'xdotool' 'patchelf' 'openssl' 'curl' 'wget' 'file')
14provides=('blinko-desktop')
15conflicts=('blinko-desktop')
16options=('!strip' '!debug' '!lto')
17source=("$_pkgname::git+${url}.git"
18 'blinko-desktop.sh'
19 'blinko-desktop.desktop')
20sha256sums=('SKIP'
21 'SKIP'
22 'SKIP')
23
24pkgver() {
25 cd "$_pkgname"
26 local _ver
27 _ver=$(grep -m1 '"version"' package.json | sed 's/.*"\([0-9][^"]*\)".*/\1/')
28 printf '%s.r%s.g%s' "$_ver" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
29}
30
31build() {
32 cd "$_pkgname"
33
34 export PRISMA_SKIP_POSTINSTALL_GENERATE=true
35 # linuxdeploy's bundled strip can't handle Arch's binaries
36 export NO_STRIP=true
37 export CARGO_HOME="$srcdir/cargo"
38
39 bun install --frozen-lockfile
40
41 cd app
42 # createUpdaterArtifacts is disabled: it requires upstream's signing key
43 bunx tauri build --bundles appimage \
44 --config '{"bundle":{"createUpdaterArtifacts":false}}'
45}
46
47package() {
48 local _bundle="$srcdir/$_pkgname/app/src-tauri/target/release/bundle/appimage"
49
50 install -Dm755 "$_bundle/Blinko_${pkgver%%.r*}_amd64.AppImage" \
51 "$pkgdir/opt/blinko-desktop/Blinko.AppImage"
52 install -Dm755 blinko-desktop.sh "$pkgdir/usr/bin/blinko-desktop"
53 install -Dm644 blinko-desktop.desktop "$pkgdir/usr/share/applications/blinko-desktop.desktop"
54 install -Dm644 "$srcdir/$_pkgname/app/src-tauri/icons/128x128.png" \
55 "$pkgdir/usr/share/icons/hicolor/128x128/apps/blinko-desktop.png"
56 install -Dm644 "$srcdir/$_pkgname/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
57}
58

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion