dell-powermanager-git
The Flutter SDK tarball is downloaded from Google's official storage.googleapis.com infrastructure (flutter_infra_release), which is the canonical Flutter release host; both sources have SKIP'd checksums which is sloppy but not malicious, and the rest of the build compiles the project's own source code without any obfuscated payloads or exfiltration.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): The Flutter SDK tarball is downloaded from Google's official storage.googleapis.com infrastructure (flutter_infra_release), which is the canonical Flutter release host; both sources have SKIP'd checksums which is sloppy but not malicious, and the rest of the build compiles the project's own source code without any obfuscated payloads or exfiltration.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:43
"https://storage.googleapis.com/flutter_infra_release/releases/stable/linux/flutter_linux_3.47.0-stable.tar.xz"
PKGBUILD
1 offending line(s) highlighted# Maintainer: alexytomi <alexytomi101@gmail.com>
pkgname=dell-powermanager-git
pkgver=0.13.0.r0.g2803dc0
pkgrel=1
pkgdesc='Cross-platform Dell Power Manager re-implementation'
arch=('x86_64')
url='https://github.com/alexVinarskis/dell-powermanager'
license=('GPL-3.0-only')
provides=('dell-powermanager')
conflicts=('dell-powermanager')
makedepends=(
# Package deps
'ninja'
'gtk3'
'sqlite'
'libsecret'
# Flutter SDK deps
'curl'
'git'
'unzip'
'xz'
'zip'
'glu'
)
depends=(
'dell-command-configure' # AUR
)
# We manually clone the flutter SDK because there is literally no
# working flutter package as of writing, using fvm seems to be
# dependent on github clone speed which as of writing, is very
# spotty/slow and fvm adds unneeded complexity.
# Sadly this means that this PKGBUILD may need flutter sdk updates
# if the program starts needing newer ones, so check that first
# if this breaks.
source=(
"git+https://github.com/alexVinarskis/dell-powermanager.git"
"https://storage.googleapis.com/flutter_infra_release/releases/stable/linux/flutter_linux_3.47.0-stable.tar.xz"
)
sha256sums=('SKIP' 'SKIP')
pkgver() {
cd "$srcdir/dell-powermanager"
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g'
}
build() {
cd "$srcdir/dell-powermanager"
# Following package.sh in the repo, which is for debian
PACKAGE="dell-powermanager"
NAME="Dell Power Manager by VA"
VERSION=$(git describe --tags)
sed -i "s|applicationName".*"|applicationName = '${NAME}';|g" ./lib/configs/constants.dart
sed -i "s|applicationPackageName".*"|applicationPackageName = '${PACKAGE}';|g" ./lib/configs/constants.dart
# Make sure this is semver. The version update checker doesn't
# seem to be built for anything else.
# Also the OTA checker can't be disabled without
# a lot of changes.
sed -i "s|applicationVersion".*"|applicationVersion = '${VERSION}';|g" ./lib/configs/constants.dart
$srcdir/flutter/bin/flutter config --enable-linux-desktop
$srcdir/flutter/bin/flutter build linux --release
}
package() {
cd "$srcdir/dell-powermanager"
local appdir="$pkgdir/opt/dell-powermanager"
install -dm755 "$appdir"
cp -a build/linux/x64/release/bundle/. "$appdir/"
install -dm755 "$pkgdir/usr/bin"
ln -s /opt/dell-powermanager/dell_powermanager \
"$pkgdir/usr/bin/dell-powermanager"
install -Dm644 \
resources/dell-powermanager.desktop \
"$pkgdir/usr/share/applications/dell-powermanager.desktop"
# Following package.sh in the repo, which is for debian
sed -i \
-e 's|{VERSION}|'"$pkgver"'|g' \
-e 's|{PACKAGE}|dell-powermanager|g' \
-e 's|{PATH_ICON}|/opt/dell-powermanager/icon.png|g' \
-e 's|{NAME}|Dell Power Manager by VA|g' \
"$pkgdir/usr/share/applications/dell-powermanager.desktop"
install -Dm644 \
resources/icon.png \
"$pkgdir/opt/dell-powermanager/icon.png"
install -Dm644 \
LICENSE \
"$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |