booruflow-bin

LOW
maintainer TheElevatedOne 0 votes scanned 2026-10-08 16:09:18.783063
View on AUR
Why flagged

The package installs a prebuilt binary from the project's official GitHub releases, which is a normal distribution method; the low severity is due to the binary not being built from source, but it comes from a trusted project host with a valid checksum.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt binary from the project's official GitHub releases, which is a normal distribution method; the low severity is due to the binary not being built from source, but it comes from a trusted project host with a valid checksum.

PKGBUILD

1# Maintainer: Adam Mlady <adam.mlady@elevated.ovh>
2
3pkgname="booruflow-bin"
4pkgdesc="An open-source, cross-platform booru browser and image downloader."
5pkgrel=1
6pkgver=0.11.0
7
8url="https://github.com/normalllll/BooruFlow"
9arch=('x86_64')
10license=('GPL-3.0-or-later')
11provides=('booruflow')
12conflicts=('booruflow')
13depends=('gtk3' 'gcc-libs')
14option=('!strip')
15
16source=(
17 "https://github.com/normalllll/BooruFlow/releases/download/v${pkgver}%2B38/linux_amd64.deb"
18)
19sha256sums=(
20 "0590147bf18df2942c4ccdd710cea10c7bd08dbc59fec6f96647867250c3e78f"
21)
22
23prepare() {
24 bsdtar -xf "${srcdir}/linux_amd64.deb" -C "${srcdir}" data.tar.zst
25 bsdtar -xf "${srcdir}/data.tar.zst" -C "${srcdir}"
26}
27
28package() {
29 # Install the application bundle and supporting files
30 install -dm755 "${pkgdir}/usr"
31 cp -a "${srcdir}/usr" "${pkgdir}/"
32
33 # Ensure wrapper is executable (already is, but explicit)
34 chmod 755 "${pkgdir}/usr/bin/booruflow"
35 chmod 755 "${pkgdir}/usr/lib/booruflow/booruflow"
36}
37

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 16:09:18 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion