booruflow-bin
The package installs a prebuilt binary from the project's official GitHub releases, which is a normal distribution method; the low severity is due to the binary not being built from source, but it comes from a trusted project host with a valid checksum.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt binary from the project's official GitHub releases, which is a normal distribution method; the low severity is due to the binary not being built from source, but it comes from a trusted project host with a valid checksum.
PKGBUILD
# Maintainer: Adam Mlady <adam.mlady@elevated.ovh>
pkgname="booruflow-bin"
pkgdesc="An open-source, cross-platform booru browser and image downloader."
pkgrel=1
pkgver=0.11.0
url="https://github.com/normalllll/BooruFlow"
arch=('x86_64')
license=('GPL-3.0-or-later')
provides=('booruflow')
conflicts=('booruflow')
depends=('gtk3' 'gcc-libs')
option=('!strip')
source=(
"https://github.com/normalllll/BooruFlow/releases/download/v${pkgver}%2B38/linux_amd64.deb"
)
sha256sums=(
"0590147bf18df2942c4ccdd710cea10c7bd08dbc59fec6f96647867250c3e78f"
)
prepare() {
bsdtar -xf "${srcdir}/linux_amd64.deb" -C "${srcdir}" data.tar.zst
bsdtar -xf "${srcdir}/data.tar.zst" -C "${srcdir}"
}
package() {
# Install the application bundle and supporting files
install -dm755 "${pkgdir}/usr"
cp -a "${srcdir}/usr" "${pkgdir}/"
# Ensure wrapper is executable (already is, but explicit)
chmod 755 "${pkgdir}/usr/bin/booruflow"
chmod 755 "${pkgdir}/usr/lib/booruflow/booruflow"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-08 16:09:18 | Low | 2 |