discord_arch_electron

LOW
maintainer Zoddo 211 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads official Discord binaries from Discord's own infrastructure (dl.discordapp.net, stable.dl2.discordapp.net) to integrate with the system Electron; this is a legitimate repackaging for security/performance, not malicious code execution or supply-chain substitution.

Triggered rules

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads official Discord binaries from Discord's own infrastructure (dl.discordapp.net, stable.dl2.discordapp.net) to integrate with the system Electron; this is a legitimate repackaging for security/performance, not malicious code execution or supply-chain substitution.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:30 source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz"
  • PKGBUILD:31 'LICENSE.html::https://discord.com/terms'
  • PKGBUILD:37 "core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"

PKGBUILD

3 offending line(s) highlighted
1# Maintainer: Zoddo <archlinux+aur@zoddo.fr>
2# Contributor: Thaodan <AUR+me@thaodan.de>
3# Contributor: Manuel Hüsers <aur@huesers.de>
4# Contributor: huyizheng
5# Contributor: johnnyapol <arch@johnnyapol.me>
6
7# Based off the discord community repo PKGBUILD by Filipe Laíns (FFY00) <lains@archlinux.org>
8
9_pkgname=discord
10_electron=electron
11pkgname=${_pkgname}_arch_electron
12pkgver=1.0.158
13pkgrel=1
14epoch=1
15pkgdesc="Discord using system provided ${_electron} for increased security and performance"
16arch=('x86_64')
17provides=("${_pkgname}")
18conflicts=("${_pkgname}")
19url='https://discord.com'
20license=('LicenseRef-custom')
21options=('!strip')
22install="$pkgname.install"
23depends=("${_electron}" 'libxss')
24makedepends=('asar'
25 'jq'
26 'python-pyelftools' # Required for Krisp patcher
27 'python-capstone') # Required for Krisp patcher
28optdepends=('libpulse: Pulseaudio support'
29 'xdg-utils: Open files')
30source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz"
31 'LICENSE.html::https://discord.com/terms'
32 'OSS-LICENSES.html::https://discord.com/licenses'
33 'discord-launcher.sh'
34 'krisp-patcher.py'
35
36 # Discord modules (from 'curl "https://updates.discord.com/distributions/app/manifests/latest?channel=stable&platform=linux&arch=x64"')
37 "core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"
38 "discord_desktop_core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_desktop_core/1/full.distro"
39 "discord_zstd-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_zstd/1/full.distro"
40 "discord_krisp-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_krisp/1/full.distro"
41 "discord_rpc-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_rpc/1/full.distro"
42 "discord_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_utils/1/full.distro"
43 "discord_voice-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_voice/1/full.distro"
44 "discord_game_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_game_utils/1/full.distro"
45 "discord_erlpack-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_erlpack/1/full.distro"
46 "discord_modules-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_modules/1/full.distro"
47 "discord_spellcheck-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_spellcheck/1/full.distro"
48 "discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro"
49 "discord_cloudsync-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_cloudsync/1/full.distro"
50 "discord_sysimg-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_sysimg/1/full.distro")
51sha512sums=('a05e3bddb4d48597ae4d56a23b2b8f8c095b853a3658e95c2a62dffedfab93b2d4f3dbd646ee3f1a8796edabb1af2c2c7fcd8ef1b0fe26ecd67e1eaa6b624f18'
52 '2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec'
53 '5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05'
54 'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1'
55 '85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'
56 'f7e4a07a277a139a0a240156b862523e68447c0360a2e252e51da74ebfaa3d50d599fc21980085342fef2e6d686570c4ea76c1941c76397ca84e849610b1d207'
57 'c66ae752a73451f5ded26fe9d46285c7c8d25b8c1224c65abf4e70a1a074fc3d1f348094a510f89a6cc996968e9c9476869c6db97bdfbc7c686f2d0e38474c5c'
58 'c48e5be6bea155191c5e294b286959d346fb0b557ca5638a90ac2b7aa4ed89ced5458d5b4627707fc0f4d7b0463410e79b8f347ddece28f18c4ed765b11c2db9'
59 '77d2ef853c8a28cfe63bc25d9145d98d71f877c30af63540d3bc9a3eb8b3b9f4559ca839f8f7b3865d8a5353240e7bb01302ac28d756f4e11ca57f79a37b02f6'
60 '4e2fcd4ea3d1053268a50977a7074065473e3add92e44ff2db6b3d914085640fefb3015885674e9f9e6ddd9012ee0cf180337c3b7b0e65e90c21d5ecf0b47344'
61 '8f943cff82db3c244fc0e933c57a3ca9c62dbf3125ed42d9da49681478781b1fb02a551ef12f491e075da89815f185bfddf2043359e302dddf1a53550b642a7a'
62 '2b324b882705745587f760753807dfeb963de21968a35680fffe9160b5e81f7f14bd8c2f89b4014af05dda936522889fc2162f87a7e8975697f985ef601fbdb3'
63 'e047736044c5d3b5155118cc4bdbc96663a78b30eb10e741440b2f7563314a9403edec8a6fb2bc7fe65104dad8553ae656a59e284ba716f9b9af0bdb7920db8c'
64 'bbc1fae0094c6a1ba788db20d1aadca82fd1483e8c302767ee113330a7678f088a812a5e1aadfafd2eff9af42791dfb87a74d7d012fb676d52a640596c5c1429'
65 '7d5a8f89ea73f35f0824a9f03aa258ce6939e9cd6d0a5aa0415c6a63f474360e59579f23b4038342fab5dae3f41379f3f55c2db71b091e1db24422fcb0c1a8d8'
66 '0e1b67a3e8025b062d47fbc878511fa08e71502969bb0b22ff161ba9c6d7be44f4e86af6a0dfdf9fb419c014d4e4f916de68b597282e385910b4e6c97414b417'
67 '7e4ca73b41e1edbf193006e95c7c94218ac0f4c84c5e7220a9591e8e96a02a3ac2eb12bebbb2f034f5758147a50361cf8c2530178aa273c7c68ba89278eff8e7'
68 '18350a7170519e1a126406a814a1502c90328ca1ab1b8f5722db109c692449d27bb25a9c781d76fc47d359064375ec300c3723cb87a1cffa7cbc484952e33fe3'
69 '92362cf99e51aae87094a74488fe79f34786021faeed9c6666b423667e31c5011a655f8ad38c9440508abefc95c0ec7ab6e15577edb950db7fcf3b8472f2e460')
70
71# Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable
72# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with
73# literal hashes, set them to SKIP with indexed assignments (pacman-contrib#119)
74# https://gitlab.archlinux.org/pacman/pacman-contrib/-/issues/119
75sha512sums[1]='SKIP'
76sha512sums[2]='SKIP'
77
78# Colored makepkg-like functions
79_all_off="$(tput sgr0)"
80_bold="${_all_off}$(tput bold)"
81_blue="${_bold}$(tput setaf 4)"
82_red="${_bold}$(tput setaf 1)"
83msg_blue() {
84 printf "${_blue} ->${_bold} $1${_all_off}\n"
85}
86error() {
87 printf "${_blue}==>${_red} ERROR:${_bold} %s${_all_off}\n" "$1" >&2
88 exit 1
89}
90
91prepare() {
92 msg_blue "Extracting core-${pkgver}.tar.br"
93 tar -xf core-${pkgver}.tar.br --use-compress-program=brotli --one-top-level=core --strip-components=1 files/
94
95 for module in discord_*.tar.br; do
96 msg_blue "Extracting ${module}"
97 tar -xf "${module}" --use-compress-program=brotli --one-top-level="modules/${module%%-*}" --strip-components=1 files/
98 done
99
100 # prepare launcher script
101 sed -i -e "s|@PKGNAME@|${_pkgname}|" \
102 -e "s|@ELECTRON@|${_electron}|" \
103 discord-launcher.sh
104
105 # fix the .desktop file
106 sed -i -e "s|Exec=.*|Exec=/usr/bin/${_pkgname}|" ${_pkgname^}/$_pkgname.desktop
107}
108
109build() {
110 msg_blue 'Patching app.asar to use system electron'
111
112 asar e core/resources/app.asar core/resources/app
113 rm core/resources/app.asar
114 sed -i \
115 -e "s|^Exec=\${exePath}$|Exec=/usr/bin/${_pkgname}|" \
116 -e "s|^Name=\${appName}$|Name=${_pkgname^}|" \
117 -e "s|^Icon=\${iconPath}$|Icon=${_pkgname}|" \
118 -e "s|resourcesPath=path_1\.default\.join(require\.main\.filename,\"\.\.\",\"\.\.\"),|resourcesPath='/usr/share/${_pkgname}/resources',|" \
119 -e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|g" \
120 core/resources/app/bundle.js
121 sed -i -e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|" core/resources/app/splashScreenPreload.js
122
123 # This is required to properly show the window icon under wayland
124 jq ".desktopName = \"${_pkgname}.desktop\"" core/resources/app/package.json > tmp.json
125 mv tmp.json core/resources/app/package.json
126
127 asar p core/resources/app core/resources/app.asar
128 rm -rf core/resources/app
129
130 # Set the newUpdater key to false in build_info.json in order to disable the new Discord updater (released on 2026-05-04, version 1.0.136),
131 # Also add a localModulesRoot key that points to the Discord modules we're packaging.
132 jq ".newUpdater = false | .localModulesRoot = \"/usr/share/${_pkgname}/modules\"" core/resources/build_info.json > tmp.json
133 mv tmp.json core/resources/build_info.json
134
135 msg_blue 'Patching Krisp to run with system electron'
136 # original: https://github.com/sersorrel/sys/blob/main/hm/discord/krisp-patcher.py
137 python krisp-patcher.py "modules/discord_krisp/discord_krisp.node" \
138 || error 'Krisp patcher failed. You can comment it out in the PKGBUILD, but Krisp will not work.'
139
140 # Krisp fails to initialize if this directory is not present (or if can't be created). Logs:
141 # [MediaEngineStore] Failed to load Krisp module: Failed to setup Krisp module, error code: -4
142 # [AVError] AV error reported: noise-canceller-error {"underlyingError":"NoiseCancellerError.KRISP_INIT_ERROR_GLOBAL_INIT"}
143 mkdir -p "modules/discord_krisp/KMS/logs"
144}
145
146package() {
147 # create necessary directories
148 install -d "${pkgdir}/usr/share/${_pkgname}"
149
150 # copy relevant data
151 cp -r core/resources/ "${pkgdir}/usr/share/${_pkgname}/"
152 cp -r modules/ "${pkgdir}/usr/share/${_pkgname}/"
153
154 # intall icon and desktop file
155 install -Dm 644 ${_pkgname^}/$_pkgname.png "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png"
156 install -Dm 644 ${_pkgname^}/$_pkgname.desktop "${pkgdir}/usr/share/applications/${_pkgname}.desktop"
157
158 # install the launch script
159 install -Dm 755 discord-launcher.sh "${pkgdir}/usr/bin/${_pkgname}"
160
161 # install licenses
162 install -Dm 644 LICENSE.html "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.html"
163 install -Dm 644 OSS-LICENSES.html "${pkgdir}/usr/share/licenses/${pkgname}/OSS-LICENSES.html"
164}
165

Changes since previous scan

--- PKGBUILD @ 2026-09-21 00:26
+++ PKGBUILD @ 2026-10-02 00:00
@@ -9,7 +9,7 @@
_pkgname=discord
_electron=electron
pkgname=${_pkgname}_arch_electron
-pkgver=1.0.157
+pkgver=1.0.158
pkgrel=1
epoch=1
pkgdesc="Discord using system provided ${_electron} for increased security and performance"
@@ -48,25 +48,25 @@
"discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro"
"discord_cloudsync-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_cloudsync/1/full.distro"
"discord_sysimg-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_sysimg/1/full.distro")
-sha512sums=('dc96d21e010b2929068c58d41e8a22954bbb4c70e4bb9c09b9b54c6398c5d1c1fc895b32fa848b861cf3751a7be6a90e7a898c93c4be57295d3f3e43d9261fa6'
+sha512sums=('a05e3bddb4d48597ae4d56a23b2b8f8c095b853a3658e95c2a62dffedfab93b2d4f3dbd646ee3f1a8796edabb1af2c2c7fcd8ef1b0fe26ecd67e1eaa6b624f18'
'2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec'
'5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05'
'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1'
'85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'
- 'ee49bca40ca1d2489536ba1c8169c6af8e0475c320be11c6ce5f9fc6fd59ad1fc675911c39bc7c9484a2ca79873c9b5ea08988668dd77db6732d6e90a858a76c'
- '3001d91cf81a46fbf827cda0fb9fd36a89551e08269f9e34d1d57cbbccf18eec8e1f434e3e94fb4a270027903485f4c8fbd434380ce37f9aa284ef270e0cc78e'
- 'aef19ce9c59a0cd965d022b26efa14c675d8d9f566155537db46e846234645129896076e62f69afaa89e4e53fe6eb0e3489fa1e83295c15839b2c94e385a0dde'
- 'a91e3240ef308fb081a68f87f8689f09a7ab8b295f1a6db05dbea3030c29b23863c2a9955249f971dc7703c365e5b6fccbdf6b9f3e5edb6f8aaec246da7794fa'
- '495d450183b6039fa38c0427b1dc4acdf8d925157621e41e03d265e3ccaa40278aec15decc8b43ab4a96e176338b1e9628ad99ea8d7d70abf8aef1edaf4005e8'
- '997446283554df96d4a09bceff705c86606170425421ae3f7d6a21be271b971971e39ea631b2a3bb6caf9bf372a628ba6b92820db466d4b25ae94ae7c526c91f'
- 'e954cfd4199490d779de622ea7721fe7b4c63ce879f662ac2ba0cd3c1cbbe68380ee8bc3dd4a0f3a405ec24ff0e7be5fad56126a44af0f13b1c6ac1af869ffae'
- 'b89aeb60f86d31483e9d23e43f2b4376e7725d3c2284eacfc9298f821a3afa2718f01bc60a12c0a154f2424536632109336c81074766a377172289ed56f0f1a6'
- 'df4ccd0c13dbe5a088ed22b8431f5a49a60dce22950a6d3a3c17eead40c8e9ef02e795aaee7a548e9e5e63c5bce5f25f01faaffd92428b169393fe19cb872d39'
- 'aef89cb3f2741c5749a63ebed0fc8194cbbedef651fe2f393fe789a123c5682ad678ebca50eca7a2c21e724714c561e6af74598481d4197d5ea48f7cfa2ee650'
- '4fa0c362e87456a2f34d822ddec99c86a61df3599b1d1c53a12f965143e4c8d517e367f4f5405703f14e8d3ce9f29d7f93e8bf036d517711a6ab7f1a1c021df6'
- '03402851bcd373c038a2c063dc33d25372f6bb04e7198c47ae8343f80e3947dd89f79d467a83760b9d54b6e463d782526ccc0018a11d57ced94907a8d989abd5'
- 'c2e02ac28992e82bd3e68da00424a21f21bfbb6094d26347e25aa0756ad9c40fc4fef885f172e3a2c0b9e101ceb56757d5bcf4624cccab4cadcbd83fe4597bf0'
- '59058457fc18912bf7f4d7c3bfadd89f748304f430a4d745fd70d723fab6bc5c56a8e11ea527ff6684688846bc17cf1f892d9b785f7dabd034581f25e99e84c7')
+ 'f7e4a07a277a139a0a240156b862523e68447c0360a2e252e51da74ebfaa3d50d599fc21980085342fef2e6d686570c4ea76c1941c76397ca84e849610b1d207'
+ 'c66ae752a73451f5ded26fe9d46285c7c8d25b8c1224c65abf4e70a1a074fc3d1f348094a510f89a6cc996968e9c9476869c6db97bdfbc7c686f2d0e38474c5c'
+ 'c48e5be6bea155191c5e294b286959d346fb0b557ca5638a90ac2b7aa4ed89ced5458d5b4627707fc0f4d7b0463410e79b8f347ddece28f18c4ed765b11c2db9'
+ '77d2ef853c8a28cfe63bc25d9145d98d71f877c30af63540d3bc9a3eb8b3b9f4559ca839f8f7b3865d8a5353240e7bb01302ac28d756f4e11ca57f79a37b02f6'
+ '4e2fcd4ea3d1053268a50977a7074065473e3add92e44ff2db6b3d914085640fefb3015885674e9f9e6ddd9012ee0cf180337c3b7b0e65e90c21d5ecf0b47344'
+ '8f943cff82db3c244fc0e933c57a3ca9c62dbf3125ed42d9da49681478781b1fb02a551ef12f491e075da89815f185bfddf2043359e302dddf1a53550b642a7a'
+ '2b324b882705745587f760753807dfeb963de21968a35680fffe9160b5e81f7f14bd8c2f89b4014af05dda936522889fc2162f87a7e8975697f985ef601fbdb3'
+ 'e047736044c5d3b5155118cc4bdbc96663a78b30eb10e741440b2f7563314a9403edec8a6fb2bc7fe65104dad8553ae656a59e284ba716f9b9af0bdb7920db8c'
+ 'bbc1fae0094c6a1ba788db20d1aadca82fd1483e8c302767ee113330a7678f088a812a5e1aadfafd2eff9af42791dfb87a74d7d012fb676d52a640596c5c1429'
+ '7d5a8f89ea73f35f0824a9f03aa258ce6939e9cd6d0a5aa0415c6a63f474360e59579f23b4038342fab5dae3f41379f3f55c2db71b091e1db24422fcb0c1a8d8'
+ '0e1b67a3e8025b062d47fbc878511fa08e71502969bb0b22ff161ba9c6d7be44f4e86af6a0dfdf9fb419c014d4e4f916de68b597282e385910b4e6c97414b417'
+ '7e4ca73b41e1edbf193006e95c7c94218ac0f4c84c5e7220a9591e8e96a02a3ac2eb12bebbb2f034f5758147a50361cf8c2530178aa273c7c68ba89278eff8e7'
+ '18350a7170519e1a126406a814a1502c90328ca1ab1b8f5722db109c692449d27bb25a9c781d76fc47d359064375ec300c3723cb87a1cffa7cbc484952e33fe3'
+ '92362cf99e51aae87094a74488fe79f34786021faeed9c6666b423667e31c5011a655f8ad38c9440508abefc95c0ec7ab6e15577edb950db7fcf3b8472f2e460')
# Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable
# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 19:35:51 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 21:26:26 Low 2
2026-09-13 00:19:54 Clean 2
2026-09-12 11:11:46 Low 1
2026-09-12 00:25:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion