cathode
maintainer kaiserbh
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package builds from the project's own source via git+https from a plausibly project-owned GitHub repo; the 'External install via cargo' is for tauri-cli in a local prefix, which is a normal build step for Tauri apps and not a remote code execution risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds from the project's own source via git+https from a plausibly project-owned GitHub repo; the 'External install via cargo' is for tauri-cli in a local prefix, which is a normal build step for Tauri apps and not a remote code execution risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
External install via pipx/uv/poetry/cargo/go/gem
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:23
cargo install --locked --version '^2' --root "$srcdir/tools" tauri-cli
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: KaiserBh <developer.kaiserbh.f01xk@simplelogin.com>
2
#
3
# PKGBUILD for Cathode, a cross-platform IPTV player (Tauri + Dioxus + mpv).
4
#
5
pkgname=cathode
6
pkgver=0.5.6 # x-release-please-version
7
pkgrel=1
8
pkgdesc="Cross-platform IPTV player (Tauri + Dioxus + mpv)"
9
arch=('x86_64')
10
url="https://github.com/kaiserbh/cathode"
11
license=('GPL-3.0-or-later')
12
depends=('mpv' 'gtk3' 'webkit2gtk-4.1')
13
makedepends=('rustup' 'git' 'dioxus-cli')
14
options=('!lto')
15
source=("$pkgname::git+https://github.com/kaiserbh/cathode.git#tag=v$pkgver")
16
sha256sums=('SKIP')
17
18
prepare() {
19
cd "$srcdir/$pkgname"
20
# Fetch git dependencies (e.g. dioxus-primitives) with the system git CLI;
21
export CARGO_NET_GIT_FETCH_WITH_CLI=true
22
# Build a pinned tauri-cli into a package-local prefix (see makedepends note).
23
cargo install --locked --version '^2' --root "$srcdir/tools" tauri-cli
24
# Pre-fetch the project's crates against the committed lockfile.
25
cargo fetch --locked
26
}
27
28
build() {
29
cd "$srcdir/$pkgname"
30
export CARGO_NET_GIT_FETCH_WITH_CLI=true
31
export PATH="$srcdir/tools/bin:$PATH"
32
# --no-bundle: produce just the release binary (installed directly; runtime
33
# libraries come from depends), while still running the frontend
34
# beforeBuildCommand (dx bundle). rust-toolchain.toml selects the toolchain.
35
cargo tauri build --no-bundle
36
}
37
38
package() {
39
cd "$srcdir/$pkgname"
40
41
install -Dm755 "target/release/cathode" "$pkgdir/usr/bin/cathode"
42
install -Dm644 "src-tauri/icons/128x128.png" \
43
"$pkgdir/usr/share/icons/hicolor/128x128/apps/cathode.png"
44
45
install -Dm644 /dev/stdin "$pkgdir/usr/share/applications/cathode.desktop" <<EOF
46
[Desktop Entry]
47
Type=Application
48
Name=Cathode
49
Comment=Cross-platform IPTV player
50
Exec=cathode
51
Icon=cathode
52
Terminal=false
53
Categories=AudioVideo;Player;TV;
54
EOF
55
}
56
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |