cwtch

maintainer iamawacko · 2 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from the project's official Git repository on a non-whitelisted but plausibly project-owned host; building from official project source is normal AUR packaging, even if the host is not on a whitelist.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's official Git repository on a non-whitelisted but plausibly project-owned host; building from official project source is normal AUR packaging, even if the host is not on a whitelist.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source=("${_pkgname}-v${pkgver}.tar.gz::https://git.openprivacy.ca/api/v1/repos/cwtch.im/${_pkgname}/archive/v${pkgver}.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: iamawacko <iamawacko@protonmail.com>
2# Contributor: Trevor Bergeron <aur@sec.gd>
3
4_pkgname=cwtch-ui
5pkgname=cwtch
6pkgver=1.16.3
7pkgrel=1
8pkgdesc="UI for Privacy Preserving Infrastructure for Asynchronous, Decentralized and Metadata Resistant Applications"
9arch=('x86_64')
10url="https://cwtch.im/"
11license=('MIT')
12conflicts=('cwtch-bin' 'cwtch-git')
13depends=('cwtch-autobindings')
14makedepends=('flutter' 'ninja')
15source=("${_pkgname}-v${pkgver}.tar.gz::https://git.openprivacy.ca/api/v1/repos/cwtch.im/${_pkgname}/archive/v${pkgver}.tar.gz")
16sha512sums=('447fd26cf5a7f51d6cae94cdde1627a5193639d16761cf2c864af8318333105a35deb8ec08ae078f5d1532567dfa2bec05c55d2d1e8b64ce4c722ef268da36c3')
17
18prepare() {
19 cd "$srcdir/$_pkgname"
20 # Remove deprecated isAlwaysShown for compat with newer dart SDKs
21 sed -re 's/(scrollbarTheme: .*)isAlwaysShown: false(, )?/\1/' -i lib/themes/opaque.dart
22 # Remove Tor binary and libCwtch.so from package script, since we don't vendor them
23 sed -re 's/^cp( -r)? linux\/(libCwtch\.so|Tor) /#\0/' -i linux/package-release.sh
24}
25
26build() {
27 cd "$srcdir/$_pkgname"
28
29 # If using the AUR 'flutter'/'flutter-beta' packages, we need a group.
30 if ! id -nG | grep -qw flutterusers ; then
31 if [ "`which flutter`" == "/usr/bin/flutter" ] ; then
32 warning "You are not in the 'flutterusers' group. The build may fail."
33 warning "Run 'sudo usermod -a -G flutterusers $USER' and reboot to fix."
34 warning "You may need to use the flutter-beta package (any channel)."
35 fi
36 fi
37
38 flutter="flutter --suppress-analytics"
39 # no way to local-enable this... let's try to clean up after ourselves
40 $flutter config | grep -qE '^\s*enable-linux-desktop: true\b' || flutter_set_linux=y
41 flutter_set_linux="$?"
42 [ "$flutter_set_linux" == "y" ] || $flutter config --enable-linux-desktop
43
44 # See https://git.openprivacy.ca/cwtch.im/cwtch-ui/src/branch/trunk/.drone.yml
45 $flutter pub get
46 $flutter build linux \
47 --dart-define BUILD_VER="${pkgver}-${pkgrel}-ARCH" \
48 --dart-define BUILD_DATE="`date +%G-%m-%d-%H-%M`"
49
50 [ "$flutter_set_linux" == "y" ] || $flutter config --no-enable-linux-desktop
51}
52
53package() {
54 cd "$srcdir/$_pkgname"
55 linux/package-release.sh
56 cd build/linux/x64/release/bundle
57 INSTALL_PREFIX="$pkgdir/usr" DESKTOP_PREFIX="/usr" ./install.sh
58}
59

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion