chatgpt-desktop-app-bin
The package downloads prebuilt .deb binaries from OpenAI's official static domain, which is plausibly the project's own infrastructure; the binaries are verified with matching checksums, and only a launcher script is replaced, posing minimal supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt .deb binaries from OpenAI's official static domain, which is plausibly the project's own infrastructure; the binaries are verified with matching checksums, and only a launcher script is replaced, posing minimal supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:62
"${_deb_x86_64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_amd64.deb"
PKGBUILD
1 offending line(s) highlighted# Maintainer: czyt <czytcn@gmail.com>
# Official downloads: https://chatgpt.com/codex/
pkgname=chatgpt-desktop-app-bin
pkgver=26.814.41407
pkgrel=1
pkgdesc="Official ChatGPT desktop app with Codex"
arch=('x86_64' 'aarch64')
url="https://chatgpt.com/codex/"
license=('custom')
depends=(
'alsa-lib'
'at-spi2-core'
'bash'
'cairo'
'dbus'
'expat'
'gcc-libs'
'gdk-pixbuf2'
'glib2'
'glibc'
'gtk3'
'libcups'
'libdrm'
'libglvnd'
'libnotify'
'libusb'
'libx11'
'libxcb'
'libxcomposite'
'libxdamage'
'libxext'
'libxfixes'
'libxkbcommon'
'libxrandr'
'mesa'
'nspr'
'nss'
'openssl'
'pango'
'systemd-libs'
'xdg-utils'
'xz'
)
optdepends=(
'apparmor: load the bundled user-namespace profile on AppArmor systems'
'git: version control integration'
)
makedepends=('libarchive')
provides=('chatgpt' 'chatgpt-desktop-app' 'openai-codex-desktop')
conflicts=('chatgpt' 'chatgpt-desktop-app' 'codex-desktop-app' 'openai-codex-desktop')
replaces=('codex-desktop-app')
options=('!debug' '!strip')
_deb_x86_64="chatgpt_${pkgver}_amd64.deb"
_deb_aarch64="chatgpt_${pkgver}_arm64.deb"
source=('chatgpt-launcher.sh')
source_x86_64=(
"${_deb_x86_64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_amd64.deb"
)
source_aarch64=(
"${_deb_aarch64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_arm64.deb"
)
noextract=("${_deb_x86_64}" "${_deb_aarch64}")
sha256sums=('56a14509725adb2ab66c6218295030f56470ecd4ca66fb47b6355809903b7382')
sha256sums_x86_64=('053d5ace91c48a17146aef02ca4abb00a2b1e94ffd15ca01891fd84a8227ca80')
sha256sums_aarch64=('223dfd7f72a515737a5065a780485f3d6a7a8df40fca4f86d028fb953f6749bf')
package() {
cd "${srcdir}"
local deb_var="_deb_${CARCH}"
local deb="${!deb_var}"
bsdtar -xOf "${deb}" data.tar.xz |
bsdtar --no-same-owner -xf - -C "${pkgdir}"
rm "${pkgdir}/usr/bin/chatgpt"
install -Dm755 chatgpt-launcher.sh "${pkgdir}/usr/bin/chatgpt"
ln -s chatgpt "${pkgdir}/usr/bin/codex-desktop"
install -Dm644 "${pkgdir}/usr/share/doc/chatgpt/copyright" \
"${pkgdir}/usr/share/licenses/${pkgname}/copyright"
# Debian package-policy files are not used on Arch Linux.
rm -rf "${pkgdir}/usr/share/doc" "${pkgdir}/usr/share/lintian"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |