circle-chain-desktop-git

maintainer zxp19821005 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The flagged `npx ts-node ./.erb/scripts/clean.js dist` call executes a local script (`clean.js`) from the cloned git repository using `ts-node`, which is installed as a local devDependency via `npm install`. This is not fetching or executing a remote package at build time — `npx` here resolves `ts-node` from the local `node_modules/.bin/` directory (installed in the preceding `npm install` step), and the script itself is part of the upstream source tree. The source is a git clone from the official GitHub repository. The npm registry mirror fallback for CN users uses npmmirror.com, which is a well-known Chinese npm mirror. The overall pattern (nvm for node version management, electron-builder with system electron, local .npmrc configuration) is a common AUR pattern for Electron apps. No binaries are fetched from unofficial hosts, no obfuscation is present, and no code is executed from outside the cloned source tree or installed npm packages. The main concern is the usual npm supply-chain risk inherent to any Node.js build, which is a general ecosystem risk rather than a specific PKGBUILD-level threat.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The flagged `npx ts-node ./.erb/scripts/clean.js dist` call executes a local script (`clean.js`) from the cloned git repository using `ts-node`, which is installed as a local devDependency via `npm install`. This is not fetching or executing a remote package at build time — `npx` here resolves `ts-node` from the local `node_modules/.bin/` directory (installed in the preceding `npm install` step), and the script itself is part of the upstream source tree. The source is a git clone from the official GitHub repository. The npm registry mirror fallback for CN users uses npmmirror.com, which is a well-known Chinese npm mirror. The overall pattern (nvm for node version management, electron-builder with system electron, local .npmrc configuration) is a common AUR pattern for Electron apps. No binaries are fetched from unofficial hosts, no obfuscation is present, and no code is executed from outside the cloned source tree or installed npm packages. The main concern is the usual npm supply-chain risk inherent to any Node.js build, which is a general ecosystem risk rather than a specific PKGBUILD-level threat.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:76 NODE_ENV=production npx ts-node ./.erb/scripts/clean.js dist

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=circle-chain-desktop-git
3_pkgname=Circlechain
4pkgver=1.1.2.r12.g42b933a
5_electronversion=20
6_nodeversion=16
7pkgrel=1
8pkgdesc="A blockchain project which is the same as bitcoin, but it has more types than bitcoin which only has coins.Circlechain has coin, identity and ownership 3 types asset.(Use system-wide electron)"
9arch=('any')
10url="https://github.com/lidh04/circle-chain-desktop"
11license=('MIT')
12conflicts=("${pkgname%-git}")
13provides=("${pkgname%-git}=${pkgver%.r*}")
14depends=(
15 "electron${_electronversion}"
16)
17makedepends=(
18 'gendesk'
19 'npm'
20 'nvm'
21 'git'
22 'curl'
23)
24source=(
25 "${pkgname%-git}.git::git+${url}"
26 "${pkgname%-git}.sh"
27)
28sha256sums=('SKIP'
29 '291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
30pkgver() {
31 cd "${srcdir}/${pkgname%-git}.git"
32 set -o pipefail
33 git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
34 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
35}
36_ensure_local_nvm() {
37 local NVM_DIR="${srcdir}/.nvm"
38 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
39 nvm install "${_nodeversion}"
40 nvm use "${_nodeversion}"
41}
42prepare() {
43 sed -e "
44 s/@electronversion@/${_electronversion}/g
45 s/@appname@/${pkgname%-git}/g
46 s/@runname@/app.asar/g
47 s/@cfgdirname@/${pkgname%-git}/g
48 s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
49 " -i "${srcdir}/${pkgname%-git}.sh"
50 _ensure_local_nvm
51 gendesk -q -f -n --pkgname="${pkgname%-git}" --pkgdesc="${pkgdesc}" --categories="Utility" --name="${_pkgname}" --exec="${pkgname%-git} %U"
52 cd "${srcdir}/${pkgname%-git}.git"
53 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
54 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
55 HOME="${srcdir}/.electron-gyp"
56 {
57 echo -e '\n'
58 #echo 'build_from_source=true'
59 echo "cache=${srcdir}/.npm_cache"
60 } >> .npmrc
61 if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
62 {
63 echo 'registry=https://registry.npmmirror.com'
64 echo 'electron_mirror=https://registry.npmmirror.com/-/binary/electron/'
65 echo 'electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/'
66 } >> .npmrc
67 find ./ -type f -name "package-lock.json" -exec sed -i "s/registry.npmjs.org/registry.npmmirror.com/g" {} +
68 fi
69 find src -type f -exec sed -i "s/process.resourcesPath/\'\/usr\/lib\/${pkgname%-git}\'/g" {} +
70 sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g;228,262d" package.json
71 NODE_ENV=development npm install
72}
73build() {
74 cd "${srcdir}/${pkgname%-git}.git"
75 electronDist="/usr/lib/electron${_electronversion}"
76 NODE_ENV=production npx ts-node ./.erb/scripts/clean.js dist
77 NODE_ENV=production npm run build
78 NODE_ENV=production npm exec -c "electron-builder --linux dir -c.electronDist=${electronDist}"
79}
80package() {
81 install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
82 install -Dm644 "${srcdir}/${pkgname%-git}.git/release/build/linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname%-git}"
83 cp -Pr --no-preserve=ownership "${srcdir}/${pkgname%-git}.git/release/build/linux-"*/resources/{app.asar.unpacked,assets} "${pkgdir}/usr/lib/${pkgname%-git}"
84 install -Dm644 "${srcdir}/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
85 icon_sizes=(16x16 24x24 32x32 48x48 64x64 96x96 128x128 256x256 512x512 1024x1024)
86 for _icons in "${icon_sizes[@]}";do
87 install -Dm644 "${srcdir}/${pkgname%-git}.git/assets/icons/${_icons}.png" \
88 "${pkgdir}/usr/share/icons/hicolor/${_icons}/apps/${pkgname%-git}.png"
89 done
90 install -Dm644 "${srcdir}/${pkgname%-git}.git/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
91}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion