clak-bin
MEDIUM
maintainer versenilvis
0 votes
scanned 2026-10-06 00:13:36.889724
Why flagged
The package installs a precompiled binary from a GitHub release with an unverifiable 'SKIP' checksum, creating a supply-chain risk if the source were compromised.
Triggered rules
Low
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
Medium
AI review of an ambiguous pattern
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 85%): The package installs a precompiled binary from a GitHub release with an unverifiable 'SKIP' checksum, creating a supply-chain risk if the source were compromised.
PKGBUILD
1
# maintainer: verse <versedev.store@proton.me>
2
pkgname=clak-bin
3
_pkgname=clak
4
pkgver=0.3.1
5
pkgrel=1
6
pkgdesc="Fast and highly stable Vietnamese input method for Fcitx5 and Wayland (precompiled binary)"
7
arch=('x86_64')
8
url="https://github.com/versenilvis/clak"
9
license=('0BSD')
10
depends=('fcitx5' 'hicolor-icon-theme' 'libinput' 'systemd-libs')
11
provides=('clak' 'fcitx5-clak')
12
conflicts=('clak' 'fcitx5-clak')
13
options=('!debug' '!strip')
14
install=clak-bin.install
15
source=("$pkgname-$pkgver.tar.gz::$url/releases/download/v$pkgver/$_pkgname-$pkgver-linux-$CARCH.tar.gz")
16
sha256sums=('SKIP')
17
18
package() {
19
cp -dr --no-preserve=ownership "$srcdir/usr" "$pkgdir/"
20
}
21
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:13:36 | Medium | 2 |
| 2026-10-05 23:40:58 | Medium | 2 |