bruno-electron

LOW
maintainer bupd 4 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The npm install in prepare() is part of building the project from its own source; the package installs only built assets from the official GitHub repo, and the undeclared package (node-addon-api) is a common build dependency needed for native Node.js addons, not a malicious external payload.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npm install in prepare() is part of building the project from its own source; the package installs only built assets from the official GitHub repo, and the undeclared package (node-addon-api) is a common build dependency needed for native Node.js addons, not a malicious external payload.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:55 npm install node-addon-api --cache "${srcdir/npm-cache}"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Dj Isaac <aur at dejay dot dev>
2# Contributor: Vianney Bouchaud <aur dot vianney at bouchaud dot org>
3
4pkgname=bruno-electron
5_pkgname=bruno
6pkgdesc="Bruno, an opensource API Client for Exploring and Testing APIs using the system provided Electron"
7pkgver=1.38.1
8pkgrel=1
9conflicts=('bruno')
10provides=('bruno')
11arch=('x86_64')
12url="https://www.usebruno.com/"
13license=('MIT')
14_electron=electron
15depends=(
16 "${_electron}>=31.2.0"
17# "nodejs>=20.9.0"
18)
19
20makedepends=(
21 'asar'
22 'nvm' # where did that bring you? back to me.
23)
24
25source=(
26 "${_pkgname}-${pkgver}.tar.gz::https://github.com/usebruno/bruno/archive/v${pkgver}.tar.gz"
27 com.usebruno.app.Bruno.desktop
28)
29
30sha256sums=('468ab677fdb381b20b1de3a3433c4b36c461f9bc85cd1326fdac8f6900f9e8dc'
31 '7bad0d66e67fdaaf99d1b7b32ba2f119b7d6dba12ecfdb398c39ee3c81bbe051')
32
33_ensure_local_nvm() {
34 # let's be sure we are starting clean
35 which nvm >/dev/null 2>&1 && nvm deactivate && nvm unload
36 export NVM_DIR="${srcdir}/.nvm"
37
38 # The init script returns 3 if version specified
39 # in ./.nvrc is not (yet) installed in $NVM_DIR
40 # but nvm itself still gets loaded ok
41 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
42}
43
44prepare() {
45 _ensure_local_nvm
46
47 cd "${_pkgname}-${pkgver}"
48
49 export HUSKY=0
50
51 nvm install
52 npm install --cache "${srcdir/npm-cache}"
53
54 # WHY DO I HAVE TO INSTALL THIS MANUALLY?
55 npm install node-addon-api --cache "${srcdir/npm-cache}"
56}
57
58build() {
59 _ensure_local_nvm
60
61 export NODE_ENV=production
62
63 cd "${_pkgname}-${pkgver}"
64
65 # build packages
66 npm run build:graphql-docs
67 npm run build:bruno-query
68 npm run build:bruno-common
69
70 # bundle js sandbox libraries
71 npm run sandbox:bundle-libraries --workspace=packages/bruno-js
72
73 # build app
74 npm run build:web
75
76 electronDist="/usr/lib/${_electron}"
77 electronVer="$(cat ${electronDist}/version)"
78 sed -i -e "s~\"dist:linux\":.*~\"dist:linux\": \"electron-builder --linux --x64 --dir --config electron-builder-config.js -c.electronDist=${electronDist} -c.electronVersion=${electronVer}\",~g" packages/bruno-electron/package.json
79
80 npm run build:electron:linux
81}
82
83package() {
84 install -Dm0644 com.usebruno.app.Bruno.desktop -t "${pkgdir}/usr/share/applications/"
85
86 cd "${_pkgname}-${pkgver}"
87
88 install -Dm0755 /dev/null "${pkgdir}/usr/bin/${_pkgname}"
89 cat >> "${pkgdir}/usr/bin/${_pkgname}" <<EOD
90#! /usr/bin/sh
91ELECTRON_IS_DEV=0 exec ${_electron} /usr/lib/bruno "\$@"
92EOD
93
94 install -Dm0644 license.md "${pkgdir}/usr/share/licenses/${_pkgname}/LICENSE"
95 install -d "${pkgdir}/usr/lib/${_pkgname}/"
96 asar e packages/bruno-electron/out/linux-unpacked/resources/app.asar "${pkgdir}/usr/lib/${_pkgname}/"
97
98 for i in 16 24 48 64 128 256 512 1024; do
99 install -Dm644 "packages/bruno-electron/resources/icons/png/${i}x${i}.png" "${pkgdir}/usr/share/icons/hicolor/${i}x${i}/apps/com.usebruno.app.Bruno.png"
100 done
101}
102

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion