deadlock-modmanager-git

LOW
maintainer stormix 0 votes scanned 2026-10-07 00:21:34.957174
View on AUR
Why flagged

The pnpm install runs on a project-owned source from GitHub, part of the normal build process for a legitimate application, with no evidence of remote code execution or supply-chain attacks.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The pnpm install runs on a project-owned source from GitHub, part of the normal build process for a legitimate application, with no evidence of remote code execution or supply-chain attacks.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:28 pnpm install --frozen-lockfile --filter @deadlock-mods/desktop...

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: stormix <hello@stormix.co>
2pkgname=deadlock-modmanager-git
3pkgver=1.0.0.r16.g2868189
4pkgrel=3
5pkgdesc='A mod manager for the Valve game Deadlock (git)'
6arch=('x86_64')
7url='https://github.com/deadlock-mod-manager/deadlock-mod-manager'
8license=('GPL-3.0-only')
9makedepends=('git' 'cargo' 'cargo-tauri' 'nodejs' 'pnpm' 'protobuf')
10depends=('webkit2gtk-4.1' 'cairo' 'desktop-file-utils' 'xdg-utils' 'gdk-pixbuf2'
11 'glib2' 'gtk3' 'libsoup3' 'pango' 'openssl' 'bzip2' 'hicolor-icon-theme'
12 'gst-plugins-good' 'glibc' 'libgcc' 'libstdc++' 'dbus')
13provides=("${pkgname%-git}")
14conflicts=("${pkgname%-git}" "${pkgname%-git}-bin")
15source=("${pkgname}::git+https://github.com/deadlock-mod-manager/deadlock-mod-manager.git")
16sha256sums=('SKIP')
17
18pkgver() {
19 cd "${srcdir}/${pkgname}"
20 git describe --tags --long --abbrev=7 --match 'v[0-9]*' \
21 | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
22}
23
24prepare() {
25 cd "${srcdir}/${pkgname}/apps/desktop"
26 # The root impeccable devDependency pulls puppeteer, whose postinstall downloads Chrome.
27 export PUPPETEER_SKIP_DOWNLOAD=1
28 pnpm install --frozen-lockfile --filter @deadlock-mods/desktop...
29
30 cd src-tauri
31 cargo fetch --locked --target "$(rustc -vV | sed -n 's/host: //p')"
32}
33
34build() {
35 export CC=gcc
36 export CXX=g++
37 export CFLAGS+=" -ffat-lto-objects"
38 export CXXFLAGS+=" -ffat-lto-objects"
39 export CARGO_TARGET_DIR="${srcdir}/${pkgname}/apps/desktop/target"
40 export VITE_API_URL="https://api.deadlockmods.app"
41 export VITE_WEB_URL="https://deadlockmods.app"
42 export VITE_AUTH_URL="https://auth.deadlockmods.app"
43
44 cd "${srcdir}/${pkgname}/apps/desktop"
45 cargo tauri build --no-bundle -- --frozen
46}
47
48package() {
49 local _srcroot="${srcdir}/${pkgname}"
50 local _tauri="${_srcroot}/apps/desktop/src-tauri"
51 local _target="${_srcroot}/apps/desktop/target"
52
53 install -Dm644 "${_srcroot}/distribution/aur/deadlock-modmanager.desktop" \
54 "${pkgdir}/usr/share/applications/deadlock-modmanager.desktop"
55
56 install -Dm755 "${_target}/release/deadlock-mod-manager" \
57 "${pkgdir}/usr/bin/deadlock-modmanager"
58 install -Dm644 "${_tauri}/icons/32x32.png" \
59 "${pkgdir}/usr/share/icons/hicolor/32x32/apps/deadlock-modmanager.png"
60 install -Dm644 "${_tauri}/icons/128x128.png" \
61 "${pkgdir}/usr/share/icons/hicolor/128x128/apps/deadlock-modmanager.png"
62 install -Dm644 "${_tauri}/icons/128x128@2x.png" \
63 "${pkgdir}/usr/share/icons/hicolor/256x256/apps/deadlock-modmanager.png"
64 install -Dm644 "${_tauri}/icons/icon.png" \
65 "${pkgdir}/usr/share/icons/hicolor/512x512/apps/deadlock-modmanager.png"
66
67 install -Dm644 "${_tauri}/dev.stormix.deadlock-mod-manager.metainfo.xml" \
68 "${pkgdir}/usr/share/metainfo/dev.stormix.deadlock-mod-manager.metainfo.xml"
69}
70

Changes since previous scan

--- PKGBUILD @ 2026-09-12 11:11
+++ PKGBUILD @ 2026-10-07 00:21
@@ -1,12 +1,12 @@
# Maintainer: stormix <hello@stormix.co>
pkgname=deadlock-modmanager-git
pkgver=1.0.0.r16.g2868189
-pkgrel=2
+pkgrel=3
pkgdesc='A mod manager for the Valve game Deadlock (git)'
arch=('x86_64')
url='https://github.com/deadlock-mod-manager/deadlock-mod-manager'
license=('GPL-3.0-only')
-makedepends=('git' 'cargo' 'cargo-tauri' 'pnpm' 'protobuf')
+makedepends=('git' 'cargo' 'cargo-tauri' 'nodejs' 'pnpm' 'protobuf')
depends=('webkit2gtk-4.1' 'cairo' 'desktop-file-utils' 'xdg-utils' 'gdk-pixbuf2'
'glib2' 'gtk3' 'libsoup3' 'pango' 'openssl' 'bzip2' 'hicolor-icon-theme'
'gst-plugins-good' 'glibc' 'libgcc' 'libstdc++' 'dbus')
@@ -23,7 +23,9 @@
prepare() {
cd "${srcdir}/${pkgname}/apps/desktop"
- pnpm install
+ # The root impeccable devDependency pulls puppeteer, whose postinstall downloads Chrome.
+ export PUPPETEER_SKIP_DOWNLOAD=1
+ pnpm install --frozen-lockfile --filter @deadlock-mods/desktop...
cd src-tauri
cargo fetch --locked --target "$(rustc -vV | sed -n 's/host: //p')"

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 00:21:34 Low 2
2026-10-07 00:04:18 Medium 1
2026-09-12 11:11:46 Clean 0
2026-06-18 16:11:54 Clean 0

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion