clak-bin

MEDIUM
maintainer versenilvis 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package installs a precompiled binary from a GitHub release with an unverifiable 'SKIP' checksum, creating a supply-chain risk if the source were compromised.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 85%): The package installs a precompiled binary from a GitHub release with an unverifiable 'SKIP' checksum, creating a supply-chain risk if the source were compromised.

PKGBUILD

1# maintainer: verse <versedev.store@proton.me>
2pkgname=clak-bin
3_pkgname=clak
4pkgver=0.3.1
5pkgrel=1
6pkgdesc="Fast and highly stable Vietnamese input method for Fcitx5 and Wayland (precompiled binary)"
7arch=('x86_64')
8url="https://github.com/versenilvis/clak"
9license=('0BSD')
10depends=('fcitx5' 'hicolor-icon-theme' 'libinput' 'systemd-libs')
11provides=('clak' 'fcitx5-clak')
12conflicts=('clak' 'fcitx5-clak')
13options=('!debug' '!strip')
14install=clak-bin.install
15source=("$pkgname-$pkgver.tar.gz::$url/releases/download/v$pkgver/$_pkgname-$pkgver-linux-$CARCH.tar.gz")
16sha256sums=('SKIP')
17
18package() {
19 cp -dr --no-preserve=ownership "$srcdir/usr" "$pkgdir/"
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Medium 2
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion