codefuse-ide-git

maintainer zxp19821005 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The `yarn add -D @electron-forge/plugin-local-electron` installs a well-known, official package from the Electron Forge ecosystem (published by the Electron Forge team on the official npm registry). This is a standard pattern used in many AUR packages that build Electron apps against the system-wide electron binary — the plugin is specifically designed to redirect electron-forge to use a local electron installation instead of downloading one. The package name is not a typo-squat; `@electron-forge/plugin-local-electron` is a legitimate scoped package under the `@electron-forge` organization. The risk is the same as any `yarn install` from package.json dependencies: registry compromise is theoretically possible but this is not an unofficial or personal host. The overall pattern (nvm for build node, yarn install, electron-forge package) is common in AUR electron packaging. The sha256sum for the .sh launcher is hardcoded (not SKIP), and the git source is from the official upstream GitHub repo. This is low risk — sloppy in that the dependency isn't pinned, but not a genuine supply-chain concern beyond normal npm usage.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 75%): The `yarn add -D @electron-forge/plugin-local-electron` installs a well-known, official package from the Electron Forge ecosystem (published by the Electron Forge team on the official npm registry). This is a standard pattern used in many AUR packages that build Electron apps against the system-wide electron binary — the plugin is specifically designed to redirect electron-forge to use a local electron installation instead of downloading one. The package name is not a typo-squat; `@electron-forge/plugin-local-electron` is a legitimate scoped package under the `@electron-forge` organization. The risk is the same as any `yarn install` from package.json dependencies: registry compromise is theoretically possible but this is not an unofficial or personal host. The overall pattern (nvm for build node, yarn install, electron-forge package) is common in AUR electron packaging. The sha256sum for the .sh launcher is hardcoded (not SKIP), and the git source is from the official upstream GitHub repo. This is low risk — sloppy in that the dependency isn't pinned, but not a genuine supply-chain concern beyond normal npm usage.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:77 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=codefuse-ide-git
3_pkgname='CodeFuse IDE'
4pkgver=0.7.0.r1.g8871332
5_electronversion=30
6_nodeversion=20
7pkgrel=1
8pkgdesc="AI Native IDE based on CodeFuse and OpenSumi.(Use system-wide electron)"
9arch=('any')
10url="https://codefuse.ai/"
11_ghurl="https://github.com/codefuse-ai/codefuse-ide"
12license=('Apache-2.0')
13conflicts=("${pkgname%-git}")
14provides=("${pkgname%-git}=${pkgver%.r*}")
15depends=(
16 "electron${_electronversion}"
17)
18makedepends=(
19 'gendesk'
20 'npm'
21 'nvm'
22 'git'
23 'curl'
24 'python'
25)
26source=(
27 "${pkgname%-git}.git::git+${_ghurl}"
28 "${pkgname%-git}.sh"
29)
30sha256sums=('SKIP'
31 '291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
32pkgver() {
33 cd "${srcdir}/${pkgname%-git}.git"
34 set -o pipefail
35 git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
36 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
37}
38_ensure_local_nvm() {
39 local NVM_DIR="${srcdir}/.nvm"
40 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
41 nvm install "${_nodeversion}"
42 nvm use "${_nodeversion}"
43}
44prepare() {
45 cd "${srcdir}/${pkgname%-git}.git"
46 sed -i -e "
47 s/@electronversion@/${_electronversion}/g
48 s/@appname@/${pkgname%-git}/g
49 s/@runname@/app/g
50 s/@cfgdirname@/${_pkgname}/g
51 s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
52 " -i "${srcdir}/${pkgname%-git}.sh"
53 _ensure_local_nvm
54 gendesk -q -f -n \
55 --pkgname="${pkgname%-git}" \
56 --pkgdesc="${pkgdesc}" \
57 --categories="Utility" \
58 --name="${pkgname%-git}" \
59 --exec="${pkgname%-git} %U"
60 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
61 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
62 HOME="${srcdir}/.electron-gyp"
63 mkdir -p "${srcdir}/.electron-gyp"
64 touch "${srcdir}/.electron-gyp/.yarnrc"
65 if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
66 {
67 echo 'npmRegistryServer: "https://registry.npmmirror.com"'
68 echo "cacheFolder: "${srcdir}"/.yarn/cache"
69 echo "globalFolder: "${srcdir}"/.yarn/global"
70 echo 'networkConcurrency: 10'
71 } >> .yarnrc.yml
72 export npm_config_electron_mirror=https://registry.npmmirror.com/-/binary/electron/
73 export npm_config_electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/
74 fi
75 sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
76 NODE_ENV=development yarn install
77 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
78}
79build() {
80 cd "${srcdir}/${pkgname%-git}.git"
81 local electronDist="/usr/lib/electron${_electronversion}"
82 sed -i "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
83 {\\
84 name: \"@electron-forge/plugin-local-electron\",\\
85 config: {\\
86 electronPath: \'${electronDist}\',\\
87 },\\
88 }," forge.config.*
89 NODE_ENV=production yarn electron-rebuild
90 NODE_ENV=production yarn electron-forge package
91}
92package() {
93 install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
94 install -Dm755 -d "${pkgdir}/usr/lib/${pkgname%-git}"
95 cp -Pr --no-preserve=ownership "${srcdir}/${pkgname%-git}.git/dist/${_pkgname}-linux-"*/resources/app "${pkgdir}/usr/lib/${pkgname%-git}"
96 install -Dm644 "${srcdir}/${pkgname%-git}.git/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
97 _icon_sizes=(256 512 1024)
98 for _icons in "${_icon_sizes[@]}";do
99 install -Dm644 "${srcdir}/${pkgname%-git}.git/assets/icon/${_icons}.png" \
100 "${pkgdir}/usr/share/icons/hicolor/${_icons}x${_icons}/apps/${pkgname%-git}.png"
101 done
102 install -Dm644 "${srcdir}/${pkgname%-git}.git/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
103}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion