coursefin
maintainer vasujain275
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package installs development tools (wails, sqlc) via 'go install' to build the application, which is a normal part of the build process for Go projects and does not introduce untrusted prebuilt binaries or remote code execution.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package installs development tools (wails, sqlc) via 'go install' to build the application, which is a normal part of the build process for Go projects and does not introduce untrusted prebuilt binaries or remote code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
External install via pipx/uv/poetry/cargo/go/gem
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:23
go install github.com/wailsapp/wails/v2/cmd/wails@latest -
PKGBUILD:26
go install github.com/sqlc-dev/sqlc/cmd/sqlc@latest
PKGBUILD
2 offending line(s) highlighted
1
# Maintainer: Vasu Jain <vasujain275@gmail.com>
2
3
pkgname=coursefin
4
pkgver=0.5.0
5
pkgrel=1
6
pkgdesc='Desktop application for managing and watching offline course content'
7
arch=('x86_64')
8
url='https://github.com/vasujain275/coursefin'
9
license=('MIT')
10
depends=('webkit2gtk-4.1' 'gtk3' 'gstreamer' 'gst-plugins-base' 'gst-plugins-good' 'gst-libav')
11
makedepends=('go>=1.24' 'pnpm' 'nodejs' 'pkgconf' 'git')
12
source=("$pkgname-$pkgver.tar.gz::https://github.com/vasujain275/coursefin/archive/refs/tags/v$pkgver.tar.gz")
13
sha256sums=('SKIP')
14
15
prepare() {
16
cd "$srcdir/$pkgname-$pkgver"
17
18
# Set up isolated Go module cache to avoid polluting the system
19
export GOPATH="$srcdir/gopath"
20
export PATH="$GOPATH/bin:$PATH"
21
22
# Install Wails CLI (not in official Arch repos — must install via go install)
23
go install github.com/wailsapp/wails/v2/cmd/wails@latest
24
25
# Install sqlc CLI (required to generate Go code from SQL queries before build)
26
go install github.com/sqlc-dev/sqlc/cmd/sqlc@latest
27
28
# Install frontend dependencies (frozen lockfile ensures reproducibility)
29
pnpm --dir frontend install --frozen-lockfile
30
}
31
32
build() {
33
cd "$srcdir/$pkgname-$pkgver"
34
35
export GOPATH="$srcdir/gopath"
36
export PATH="$GOPATH/bin:$PATH"
37
38
# Respect system compiler flags for hardening / optimisation
39
export CGO_CFLAGS="${CFLAGS:-}"
40
export CGO_CXXFLAGS="${CXXFLAGS:-}"
41
export CGO_LDFLAGS="${LDFLAGS:-}"
42
43
# Build as position-independent executable (security best practice)
44
export GOFLAGS="-buildmode=pie"
45
46
# Generate type-safe Go code from SQL queries — MUST run before wails build
47
sqlc generate
48
49
# Build the Wails application
50
# -tags webkit2_41 required for webkit2gtk-4.1 (linker errors without it)
51
# -trimpath strips build paths for reproducibility (AUR best practice)
52
wails build \
53
-platform linux/amd64 \
54
-clean \
55
-o coursefin \
56
-ldflags "-X main.version=$pkgver" \
57
-tags webkit2_41 \
58
-trimpath
59
}
60
61
package() {
62
cd "$srcdir/$pkgname-$pkgver"
63
64
# Main binary
65
install -Dm755 build/bin/coursefin "$pkgdir/usr/bin/coursefin"
66
67
# Desktop entry
68
install -Dm644 packaging/coursefin.desktop "$pkgdir/usr/share/applications/coursefin.desktop"
69
70
# Application icon (512×512 PNG)
71
install -Dm644 build/appicon.png "$pkgdir/usr/share/icons/hicolor/512x512/apps/coursefin.png"
72
73
# License
74
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
75
76
# Clean up Go module cache to avoid bloating the package build directory
77
go clean -modcache
78
}
79
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |