codefuse-ide-git
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 75%): The `yarn add -D @electron-forge/plugin-local-electron` installs a well-known, official package from the Electron Forge ecosystem (published by the Electron Forge team on the official npm registry). This is a standard pattern used in many AUR packages that build Electron apps against the system-wide electron binary — the plugin is specifically designed to redirect electron-forge to use a local electron installation instead of downloading one. The package name is not a typo-squat; `@electron-forge/plugin-local-electron` is a legitimate scoped package under the `@electron-forge` organization. The risk is the same as any `yarn install` from package.json dependencies: registry compromise is theoretically possible but this is not an unofficial or personal host. The overall pattern (nvm for build node, yarn install, electron-forge package) is common in AUR electron packaging. The sha256sum for the .sh launcher is hardcoded (not SKIP), and the git source is from the official upstream GitHub repo. This is low risk — sloppy in that the dependency isn't pinned, but not a genuine supply-chain concern beyond normal npm usage.
1 higher static finding superseded - not the current verdict (shown for transparency)
npm_install_external
Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.
-
PKGBUILD:77
NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
PKGBUILD
1 offending line(s) highlighted# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
pkgname=codefuse-ide-git
_pkgname='CodeFuse IDE'
pkgver=0.7.0.r1.g8871332
_electronversion=30
_nodeversion=20
pkgrel=1
pkgdesc="AI Native IDE based on CodeFuse and OpenSumi.(Use system-wide electron)"
arch=('any')
url="https://codefuse.ai/"
_ghurl="https://github.com/codefuse-ai/codefuse-ide"
license=('Apache-2.0')
conflicts=("${pkgname%-git}")
provides=("${pkgname%-git}=${pkgver%.r*}")
depends=(
"electron${_electronversion}"
)
makedepends=(
'gendesk'
'npm'
'nvm'
'git'
'curl'
'python'
)
source=(
"${pkgname%-git}.git::git+${_ghurl}"
"${pkgname%-git}.sh"
)
sha256sums=('SKIP'
'291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
pkgver() {
cd "${srcdir}/${pkgname%-git}.git"
set -o pipefail
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
}
_ensure_local_nvm() {
local NVM_DIR="${srcdir}/.nvm"
source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
nvm install "${_nodeversion}"
nvm use "${_nodeversion}"
}
prepare() {
cd "${srcdir}/${pkgname%-git}.git"
sed -i -e "
s/@electronversion@/${_electronversion}/g
s/@appname@/${pkgname%-git}/g
s/@runname@/app/g
s/@cfgdirname@/${_pkgname}/g
s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
" -i "${srcdir}/${pkgname%-git}.sh"
_ensure_local_nvm
gendesk -q -f -n \
--pkgname="${pkgname%-git}" \
--pkgdesc="${pkgdesc}" \
--categories="Utility" \
--name="${pkgname%-git}" \
--exec="${pkgname%-git} %U"
export ELECTRON_SKIP_BINARY_DOWNLOAD=1
export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
HOME="${srcdir}/.electron-gyp"
mkdir -p "${srcdir}/.electron-gyp"
touch "${srcdir}/.electron-gyp/.yarnrc"
if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
{
echo 'npmRegistryServer: "https://registry.npmmirror.com"'
echo "cacheFolder: "${srcdir}"/.yarn/cache"
echo "globalFolder: "${srcdir}"/.yarn/global"
echo 'networkConcurrency: 10'
} >> .yarnrc.yml
export npm_config_electron_mirror=https://registry.npmmirror.com/-/binary/electron/
export npm_config_electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/
fi
sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
NODE_ENV=development yarn install
NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
}
build() {
cd "${srcdir}/${pkgname%-git}.git"
local electronDist="/usr/lib/electron${_electronversion}"
sed -i "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
{\\
name: \"@electron-forge/plugin-local-electron\",\\
config: {\\
electronPath: \'${electronDist}\',\\
},\\
}," forge.config.*
NODE_ENV=production yarn electron-rebuild
NODE_ENV=production yarn electron-forge package
}
package() {
install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
install -Dm755 -d "${pkgdir}/usr/lib/${pkgname%-git}"
cp -Pr --no-preserve=ownership "${srcdir}/${pkgname%-git}.git/dist/${_pkgname}-linux-"*/resources/app "${pkgdir}/usr/lib/${pkgname%-git}"
install -Dm644 "${srcdir}/${pkgname%-git}.git/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
_icon_sizes=(256 512 1024)
for _icons in "${_icon_sizes[@]}";do
install -Dm644 "${srcdir}/${pkgname%-git}.git/assets/icon/${_icons}.png" \
"${pkgdir}/usr/share/icons/hicolor/${_icons}x${_icons}/apps/${pkgname%-git}.png"
done
install -Dm644 "${srcdir}/${pkgname%-git}.git/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |