blockwork-git
Package builds from the project's own GitHub source; pnpm install runs against the project's own ui/ directory (normal frontend dependency resolution), not an undeclared external package; the few-votes/new-upload concern is minor and not indicative of malice.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Package builds from the project's own GitHub source; pnpm install runs against the project's own ui/ directory (normal frontend dependency resolution), not an undeclared external package; the few-votes/new-upload concern is minor and not indicative of malice.
1 higher static finding superseded - not the current verdict (shown for transparency)
npm_install_external
Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.
-
PKGBUILD:34
pnpm install --dir ui
PKGBUILD
1 offending line(s) highlighted# Maintainer: Ethan Stokes <erstokes10@gmail.com>
pkgname=blockwork-git
pkgver=0.5.0.r280.0aef58e
pkgrel=1
pkgdesc='A Tauri app to visually create and run automation.'
url='https://github.com/EthanRStokes/Blockwork'
arch=('x86_64')
license=('GPL-3.0-only')
makedepends=('rust' 'git' 'gcc' 'glibc' 'pnpm' 'cmake' 'ninja' 'curl' 'pkgconf'
'gtk3' 'webkit2gtk-4.1' 'libsoup3' 'libappindicator' 'dbus')
depends=(
'gtk3' 'nss' 'alsa-lib' 'hicolor-icon-theme' 'libxss' 'webkit2gtk-4.1'
'libsoup3' 'libappindicator'
'libgcc' 'glibc'
)
conflicts=('blockwork')
provides=('blockwork')
source=("git+https://github.com/EthanRStokes/Blockwork")
sha256sums=('SKIP')
options=('!lto')
pkgver() {
cd "$srcdir/Blockwork"
printf "%s.r%s.%s" "$(git describe --tags --abbrev=0 | sed 's/^v//')" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
}
prepare() {
cd "$srcdir/Blockwork"
git reset --hard HEAD
git_tag="$(git describe --tags --abbrev=0 | sed 's/^v//')"
cargo fetch
pnpm install --dir ui
}
build() {
cd "$srcdir/Blockwork"
export BLOCKWORK_PNPM_OFFLINE=1
cargo build --release --frozen
}
package() {
cd "$srcdir/Blockwork"
local libdir="$pkgdir/usr/lib/blockwork"
# Binary's RUNPATH is $ORIGIN, so the CEF runtime payload (libcef.so,
# GL/Vulkan shims, *.pak, icudtl.dat, locales/, ...) has to live alongside
# it in a private libdir, not /usr/bin.
install -Dm755 "target/release/blockwork" "$libdir/blockwork"
install -Dm755 "target/release/libcef.so" "$libdir/libcef.so"
install -Dm755 "target/release/libEGL.so" "$libdir/libEGL.so"
install -Dm755 "target/release/libGLESv2.so" "$libdir/libGLESv2.so"
install -Dm755 "target/release/libvk_swiftshader.so" "$libdir/libvk_swiftshader.so"
install -Dm755 "target/release/libvulkan.so.1" "$libdir/libvulkan.so.1"
install -Dm755 "target/release/chrome-sandbox" "$libdir/chrome-sandbox"
install -Dm644 "target/release/vk_swiftshader_icd.json" "$libdir/vk_swiftshader_icd.json"
install -Dm644 "target/release/icudtl.dat" "$libdir/icudtl.dat"
install -Dm644 "target/release/v8_context_snapshot.bin" "$libdir/v8_context_snapshot.bin"
install -Dm644 "target/release/chrome_100_percent.pak" "$libdir/chrome_100_percent.pak"
install -Dm644 "target/release/chrome_200_percent.pak" "$libdir/chrome_200_percent.pak"
install -Dm644 "target/release/resources.pak" "$libdir/resources.pak"
cp -r "target/release/locales" "$libdir/locales"
install -d "$pkgdir/usr/bin"
ln -sf /usr/lib/blockwork/blockwork "$pkgdir/usr/bin/blockwork"
install -Dm644 "res/icons/blockwork.png" "$pkgdir"/usr/share/icons/hicolor/256x256/apps/blockwork.png
install -Dm644 "res/blockwork.desktop" "$pkgdir"/usr/share/applications/blockwork.desktop
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-09 00:04:09 | Low | 3 |
| 2026-09-08 21:20:15 | Low | 3 |
| 2026-09-08 21:18:22 | Medium | 2 |