capture-studio-bin

MEDIUM
maintainer Felitendo 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Installs a prebuilt proprietary binary (Electron/Flatpak bundle) downloaded from downloads.tenzen.studio, which is the project's own domain but is a small/new vendor with few AUR votes; the binary is not independently verifiable beyond the provided sha256sum, making it a medium-risk prebuilt from a plausible but unestablished official source.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:21 source=("${_bundle}::https://downloads.tenzen.studio/desktop/stable/linux/${pkgver}/${_bundle}")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 65%): Installs a prebuilt proprietary binary (Electron/Flatpak bundle) downloaded from downloads.tenzen.studio, which is the project's own domain but is a small/new vendor with few AUR votes; the binary is not independently verifiable beyond the provided sha256sum, making it a medium-risk prebuilt from a plausible but unestablished official source.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Felitendo
2# This PKGBUILD is updated automatically:
3# https://git.felo.gg/Felitendo/PKGBUILDS
4
5pkgname=capture-studio-bin
6_pkgname=tenzen
7pkgver=0.1.32
8pkgrel=1
9pkgdesc="Record and edit product demos: cut pauses, add zooms and captions (upstream Flatpak bundle)"
10arch=('x86_64')
11url="https://tenzen.studio"
12license=('LicenseRef-proprietary')
13depends=('gtk3' 'nss' 'alsa-lib' 'ffmpeg' 'python-xlib')
14optdepends=('libpulse: record system audio')
15makedepends=('ostree' 'asar')
16provides=('capture-studio')
17# called tenzen-studio-bin on the AUR before
18conflicts=('capture-studio' 'tenzen-studio-bin')
19options=('!strip' '!debug')
20_bundle="Capture-Studio-${pkgver}-linux-x64.flatpak"
21source=("${_bundle}::https://downloads.tenzen.studio/desktop/stable/linux/${pkgver}/${_bundle}")
22noextract=("${_bundle}")
23sha256sums=('80958f46ebcec4197ca77e759f98ca7e6f496205070be57c487c1fa463624e3b')
24
25prepare() {
26 # A Flatpak bundle is an OSTree static delta carrying a single commit:
27 # apply it to a throwaway repository and check that commit out.
28 rm -rf repo flatpak
29 ostree init --repo=repo --mode=bare-user-only
30 ostree static-delta apply-offline --repo=repo "${_bundle}"
31
32 local _commit
33 _commit="$(find repo/objects -name '*.commit')"
34 _commit="$(basename "$(dirname "${_commit}")")$(basename "${_commit}" .commit)"
35 ostree checkout --repo=repo --user-mode "${_commit}" flatpak
36
37 # the bundle exports no icon - the app's own is only inside app.asar
38 asar extract-file flatpak/files/lib/com.tenzen.desktop/resources/app.asar \
39 dist/assets/brand/icon.png
40}
41
42package() {
43 install -d "${pkgdir}/opt/${pkgname}"
44 cp -a "${srcdir}/flatpak/files/lib/com.tenzen.desktop/." "${pkgdir}/opt/${pkgname}/"
45
46 install -d "${pkgdir}/usr/bin"
47 ln -s "/opt/${pkgname}/${_pkgname}" "${pkgdir}/usr/bin/${_pkgname}"
48
49 # named after the app's desktopName, so windows are matched to the entry
50 install -Dm644 "${srcdir}/flatpak/files/share/applications/com.tenzen.desktop.desktop" \
51 "${pkgdir}/usr/share/applications/${_pkgname}.desktop"
52 sed -i \
53 -e "s|^Exec=.*|Exec=${_pkgname} %U|" \
54 -e "s|^Icon=.*|Icon=${_pkgname}|" \
55 "${pkgdir}/usr/share/applications/${_pkgname}.desktop"
56
57 # 1024x1024, which the hicolor theme has no directory for
58 install -Dm644 "${srcdir}/icon.png" "${pkgdir}/usr/share/pixmaps/${_pkgname}.png"
59
60 # A custom licence has to ship its terms. Upstream publishes none as a file,
61 # so what goes in is the reference to the terms it is used under, next to
62 # the notices for everything bundled with it, which the app dir does carry.
63 install -Dm644 /dev/stdin "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE" <<'EOF'
64Capture Studio is proprietary software, distributed by Tenzen Studio.
65
66It is not covered by a free-software licence: use is governed by the terms
67of service the vendor publishes, and redistribution of the build this
68package installs is not granted by them.
69
70Terms of service: https://tenzen.studio/legal/terms-of-service/
71EOF
72
73 ln -s "/opt/${pkgname}/resources/THIRD_PARTY_NOTICES.txt" \
74 "${pkgdir}/usr/share/licenses/${pkgname}/THIRD_PARTY_NOTICES.txt"
75 ln -s "/opt/${pkgname}/LICENSE.electron.txt" \
76 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.electron.txt"
77 ln -s "/opt/${pkgname}/LICENSES.chromium.html" \
78 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSES.chromium.html"
79}
80

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Medium 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion