discord_arch_electron
maintainer Zoddo
· 211 votes
· scanned 2026-08-18 00:03:42.021799
LOW
View on AUR ↗
Why flagged
The package downloads official Discord binaries from Discord's own infrastructure (discordapp.net, dl2.discordapp.net) which are plausibly the project's official sources; despite the static analyzer flagging non-standard hosts, these are legitimate release endpoints, and the package builds from verifiable upstream sources without executing untrusted remote code.
Triggered rules
LOW
AI review
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads official Discord binaries from Discord's own infrastructure (discordapp.net, dl2.discordapp.net) which are plausibly the project's official sources; despite the static analyzer flagging non-standard hosts, these are legitimate release endpoints, and the package builds from verifiable upstream sources without executing untrusted remote code.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:30
source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz" -
PKGBUILD:31
'LICENSE.html::https://discord.com/terms' -
PKGBUILD:37
"core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"
PKGBUILD
3 offending line(s) highlighted
1
# Maintainer: Zoddo <archlinux+aur@zoddo.fr>
2
# Contributor: Thaodan <AUR+me@thaodan.de>
3
# Contributor: Manuel Hüsers <aur@huesers.de>
4
# Contributor: huyizheng
5
# Contributor: johnnyapol <arch@johnnyapol.me>
6
7
# Based off the discord community repo PKGBUILD by Filipe Laíns (FFY00) <lains@archlinux.org>
8
9
_pkgname=discord
10
_electron=electron
11
pkgname=${_pkgname}_arch_electron
12
pkgver=1.0.150
13
pkgrel=1
14
epoch=1
15
pkgdesc="Discord using system provided ${_electron} for increased security and performance"
16
arch=('x86_64')
17
provides=("${_pkgname}")
18
conflicts=("${_pkgname}")
19
url='https://discord.com'
20
license=('LicenseRef-custom')
21
options=('!strip')
22
install="$pkgname.install"
23
depends=("${_electron}" 'libxss')
24
makedepends=('asar'
25
'jq'
26
'python-pyelftools' # Required for Krisp patcher
27
'python-capstone') # Required for Krisp patcher
28
optdepends=('libpulse: Pulseaudio support'
29
'xdg-utils: Open files')
30
source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz"
31
'LICENSE.html::https://discord.com/terms'
32
'OSS-LICENSES.html::https://discord.com/licenses'
33
'discord-launcher.sh'
34
'krisp-patcher.py'
35
36
# Discord modules (from 'curl "https://updates.discord.com/distributions/app/manifests/latest?channel=stable&platform=linux&arch=x64"')
37
"core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"
38
"discord_desktop_core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_desktop_core/1/full.distro"
39
"discord_zstd-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_zstd/1/full.distro"
40
"discord_krisp-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_krisp/1/full.distro"
41
"discord_rpc-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_rpc/1/full.distro"
42
"discord_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_utils/1/full.distro"
43
"discord_voice-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_voice/1/full.distro"
44
"discord_game_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_game_utils/1/full.distro"
45
"discord_erlpack-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_erlpack/1/full.distro"
46
"discord_modules-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_modules/1/full.distro"
47
"discord_spellcheck-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_spellcheck/1/full.distro"
48
"discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro")
49
sha512sums=('ef38c8c9dbdcecdb0d08202d5576ccfdfa7789b7bf3a5c5b41bffba3308ecd738a1285e89514407968aa1f59d0a3693582b3dd77c9b1e9891180365e32549b2c'
50
'2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec'
51
'5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05'
52
'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1'
53
'85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'
54
'f0a322304334265bc3ee1485eec718df70320a089992ac8c4c2802ce418e8d58d5b1fcf700ab98216f81512f5aeb4e29fedbf4dbddcc465ee90c9b815d4bc1e7'
55
'a96fbea3946631a63210812bb67e9921fdfc2c415e120e1919c1ec4880187b6cd9433668c5ca5fdbbfcc1c23c6a759995d734f0e9096baed4dea5da8eac9a536'
56
'a33345164429656bbcc28c48b6d82bf39ef622753686447199661ae2cb8a11780080db02a0a20d838a2dfb2625e4599478f8b16ea120c3ce250193f6133effd5'
57
'0464dada650407f44e7d3fd378e2fee36496dc898f25e2e486bb993d01afbc5233228b61ffa76a68ededba40887c91938d06c149280ca56e6c58790838d3a8e2'
58
'75fb9521399db1ffac32b97baa6ed09055b243a83a2b83864f8ba52060cc204b308305b7d917d3e2c78f7aaeaeed2ea23b927cc34d973446907ed4f403dbd75f'
59
'ceb6589cd74c06766d26311422d1522f88dbcb569d7c600c0d1e915404f19bf8d35c310d6c6aa1813477809e0de21c0fbc7a4a74eaafd31b2e50e16cded8fdb7'
60
'afa90192782ff0f7a03d9b0f0e3a53258ef7bb632ec991513c349d6b859cf26264f6cd1b9d54a96e9bc91afe1669bd849752aec22b5010c92cda0ef59e513ddd'
61
'c92c12100a5181309503c1ba2ffd41a9e9287b21645d86119ef823f1192958ee6cfa6fcce657647b8cfdc65cad8b767cce53cb3300c996875343fe2c1d1faa14'
62
'621291c04f248d69e9ae0022d84e6903b375e75598ea3198f787c94fd4efe1b944df42a9b8a6974ef5cdc18de3f7db03da26c73a7bf176f2d3524d6a298e3ea9'
63
'178f3b9089015712c7d487c3da340942b2b445cdb88c1e6f27579f25415b4526e671438019b6ba55827127d53fe77830053d96456935aabf9a4ebf77a8b819d7'
64
'ce8bf2acba824bb3bd400b13744498b65e295fc4dd586a7306ddcd53e41c8b14435d4ca0319bc956868a1fbd6b7ecf062379ba925a2a0f356b7e13e11159a512'
65
'02d447669047ee1a94430633614c7eaa5f582dc80581464635b2beb36d418e6318937369aa3a1b3d59f36ccee62b6520abd55092c8ef49dd9e7a0950230a114e')
66
67
# Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable
68
# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with
69
# literal hashes, set them to SKIP with indexed assignments (pacman-contrib#119)
70
# https://gitlab.archlinux.org/pacman/pacman-contrib/-/issues/119
71
sha512sums[1]='SKIP'
72
sha512sums[2]='SKIP'
73
74
# Colored makepkg-like functions
75
_all_off="$(tput sgr0)"
76
_bold="${_all_off}$(tput bold)"
77
_blue="${_bold}$(tput setaf 4)"
78
_red="${_bold}$(tput setaf 1)"
79
msg_blue() {
80
printf "${_blue} ->${_bold} $1${_all_off}\n"
81
}
82
error() {
83
printf "${_blue}==>${_red} ERROR:${_bold} %s${_all_off}\n" "$1" >&2
84
exit 1
85
}
86
87
prepare() {
88
msg_blue "Extracting core-${pkgver}.tar.br"
89
tar -xf core-${pkgver}.tar.br --use-compress-program=brotli --one-top-level=core --strip-components=1 files/
90
91
for module in discord_*.tar.br; do
92
msg_blue "Extracting ${module}"
93
tar -xf "${module}" --use-compress-program=brotli --one-top-level="modules/${module%%-*}" --strip-components=1 files/
94
done
95
96
# prepare launcher script
97
sed -i -e "s|@PKGNAME@|${_pkgname}|" \
98
-e "s|@ELECTRON@|${_electron}|" \
99
discord-launcher.sh
100
101
# fix the .desktop file
102
sed -i -e "s|Exec=.*|Exec=/usr/bin/${_pkgname}|" ${_pkgname^}/$_pkgname.desktop
103
}
104
105
build() {
106
msg_blue 'Patching app.asar to use system electron'
107
108
asar e core/resources/app.asar core/resources/app
109
rm core/resources/app.asar
110
sed -i \
111
-e "s|^Exec=\${exePath}$|Exec=/usr/bin/${_pkgname}|" \
112
-e "s|^Name=\${appName}$|Name=${_pkgname^}|" \
113
-e "s|^Icon=\${iconPath}$|Icon=${_pkgname}|" \
114
-e "s|resourcesPath=path_1\.default\.join(require\.main\.filename,\"\.\.\",\"\.\.\"),|resourcesPath='/usr/share/${_pkgname}/resources',|" \
115
-e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|g" \
116
core/resources/app/bundle.js
117
sed -i -e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|" core/resources/app/splashScreenPreload.js
118
119
# This is required to properly show the window icon under wayland
120
jq ".desktopName = \"${_pkgname}.desktop\"" core/resources/app/package.json > tmp.json
121
mv tmp.json core/resources/app/package.json
122
123
asar p core/resources/app core/resources/app.asar
124
rm -rf core/resources/app
125
126
# Set the newUpdater key to false in build_info.json in order to disable the new Discord updater (released on 2026-05-04, version 1.0.136),
127
# Also add a localModulesRoot key that points to the Discord modules we're packaging.
128
jq ".newUpdater = false | .localModulesRoot = \"/usr/share/${_pkgname}/modules\"" core/resources/build_info.json > tmp.json
129
mv tmp.json core/resources/build_info.json
130
131
msg_blue 'Patching Krisp to run with system electron'
132
# original: https://github.com/sersorrel/sys/blob/main/hm/discord/krisp-patcher.py
133
python krisp-patcher.py "modules/discord_krisp/discord_krisp.node" \
134
|| error 'Krisp patcher failed. You can comment it out in the PKGBUILD, but Krisp will not work.'
135
136
# Krisp fails to initialize if this directory is not present (or if can't be created). Logs:
137
# [MediaEngineStore] Failed to load Krisp module: Failed to setup Krisp module, error code: -4
138
# [AVError] AV error reported: noise-canceller-error {"underlyingError":"NoiseCancellerError.KRISP_INIT_ERROR_GLOBAL_INIT"}
139
mkdir -p "modules/discord_krisp/KMS/logs"
140
}
141
142
package() {
143
# create necessary directories
144
install -d "${pkgdir}/usr/share/${_pkgname}"
145
146
# copy relevant data
147
cp -r core/resources/ "${pkgdir}/usr/share/${_pkgname}/"
148
cp -r modules/ "${pkgdir}/usr/share/${_pkgname}/"
149
150
# intall icon and desktop file
151
install -Dm 644 ${_pkgname^}/$_pkgname.png "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png"
152
install -Dm 644 ${_pkgname^}/$_pkgname.desktop "${pkgdir}/usr/share/applications/${_pkgname}.desktop"
153
154
# install the launch script
155
install -Dm 755 discord-launcher.sh "${pkgdir}/usr/bin/${_pkgname}"
156
157
# install licenses
158
install -Dm 644 LICENSE.html "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.html"
159
install -Dm 644 OSS-LICENSES.html "${pkgdir}/usr/share/licenses/${pkgname}/OSS-LICENSES.html"
160
}
161
Changes since previous scan
--- PKGBUILD @ 2026-07-22 00:29+++ PKGBUILD @ 2026-08-18 00:03@@ -9,7 +9,7 @@ _pkgname=discord _electron=electron pkgname=${_pkgname}_arch_electron-pkgver=1.0.149+pkgver=1.0.150 pkgrel=1 epoch=1 pkgdesc="Discord using system provided ${_electron} for increased security and performance"@@ -46,23 +46,23 @@ "discord_modules-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_modules/1/full.distro" "discord_spellcheck-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_spellcheck/1/full.distro" "discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro")-sha512sums=('07cec6aea9e36ffe7d786b55ea76f38e7469d14fc2c2d853686230f416f4e07886f02c883d929338d4b87c3d7a0b412f0e0da94f62f6b976d65a59dab759bff0'+sha512sums=('ef38c8c9dbdcecdb0d08202d5576ccfdfa7789b7bf3a5c5b41bffba3308ecd738a1285e89514407968aa1f59d0a3693582b3dd77c9b1e9891180365e32549b2c' '2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec' '5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05' 'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1' '85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'- '8a630c3376cf7069f57ca22f2420e11a834c57be8a7016b9ae7125d4bd2a61b3456ba217b075e8554bfdfde3e4f59e4ff8758370641389c388af5a3383642c14'- '21a12d18a330046d9d9dd7593be827b40baa4cf3915ce7968a279b43febb99c4c8a4134d2f26f3649cd991559fe155699cd5feb91bd97510bc2323de8d033bc2'- '810c1219f3d008b945e75951d468d64aed2b342208c1eb9756374a880283a8a9984cf6bfa94e608fe48b3de8bdbf75f80789a1f6c1987637933e776b035b2a0a'- '905e69d2af3615c80dd772d0096cb9a3773cfa42d4616f7f1709d78a4b0b8c9de19fd62d5c68943bd489fbb931aea593c1c5c67cf1c89c20d01b74158b963a81'- 'f65e4f4b20eeac3b0efc958592fb184521b3c74d4ef95ebf12783bd057fa777ed1ff0c7b0a59369c50dc089a13f15d0799a461747d670fc37a171bb637b27ac8'- '3d7410f8bdaad81563696eba0c185d187052289c29d8f23eed7067e9725e95cfa18d3ffd49c69431bf90bff943af63dcd1d823cfb0c8ee5f90a2ce8a752439c4'- '11cea4c898b7290c73f3cc9aebfb4b115709487710cfe5a15843c9c21003714a57ade0440db680f44ae2ad202485e4ce302e99b44e20a4d3761b1d49b0f87192'- 'e0f8c7c4b16d0ec39fa0e7b04954135568778e431f88aecc1292ec953a33278733f155ff876b2e4150c80894fadefbc99f8f0d7d7c6acf5cd093b098fb3be1bd'- 'c3c48374265aa106301020463416133975536ad99e7c00e7617714270d9ee470b0143800216494fde14e2c2409322ee6dafed01497d68fda8af53f9f8ef29f23'- '6e4e6c8d8d7338b88e3875a863b003472d46991b60f8df545a282efd0f09d0d6ddf53c813b5c394b42ce5d6bc489e6d3febb71e5d88a9bc0d623a467aef87416'- '22a795896e538aa8065001acb0ea66363a879db672e8d72cea85dea4f516b68a341ef33b4516cf968f1215b17b7d434ae454ff55c94151a27086b87394460380'- '802492d1d83dd3f197eb0e7a3fcde1f8b02a664d198729fc81b0c81a811bf29c2d0bfb7592a52f6e165efaaed9bdcea91a43000cb0d2bc16a8d63d62f06901f6')+ 'f0a322304334265bc3ee1485eec718df70320a089992ac8c4c2802ce418e8d58d5b1fcf700ab98216f81512f5aeb4e29fedbf4dbddcc465ee90c9b815d4bc1e7'+ 'a96fbea3946631a63210812bb67e9921fdfc2c415e120e1919c1ec4880187b6cd9433668c5ca5fdbbfcc1c23c6a759995d734f0e9096baed4dea5da8eac9a536'+ 'a33345164429656bbcc28c48b6d82bf39ef622753686447199661ae2cb8a11780080db02a0a20d838a2dfb2625e4599478f8b16ea120c3ce250193f6133effd5'+ '0464dada650407f44e7d3fd378e2fee36496dc898f25e2e486bb993d01afbc5233228b61ffa76a68ededba40887c91938d06c149280ca56e6c58790838d3a8e2'+ '75fb9521399db1ffac32b97baa6ed09055b243a83a2b83864f8ba52060cc204b308305b7d917d3e2c78f7aaeaeed2ea23b927cc34d973446907ed4f403dbd75f'+ 'ceb6589cd74c06766d26311422d1522f88dbcb569d7c600c0d1e915404f19bf8d35c310d6c6aa1813477809e0de21c0fbc7a4a74eaafd31b2e50e16cded8fdb7'+ 'afa90192782ff0f7a03d9b0f0e3a53258ef7bb632ec991513c349d6b859cf26264f6cd1b9d54a96e9bc91afe1669bd849752aec22b5010c92cda0ef59e513ddd'+ 'c92c12100a5181309503c1ba2ffd41a9e9287b21645d86119ef823f1192958ee6cfa6fcce657647b8cfdc65cad8b767cce53cb3300c996875343fe2c1d1faa14'+ '621291c04f248d69e9ae0022d84e6903b375e75598ea3198f787c94fd4efe1b944df42a9b8a6974ef5cdc18de3f7db03da26c73a7bf176f2d3524d6a298e3ea9'+ '178f3b9089015712c7d487c3da340942b2b445cdb88c1e6f27579f25415b4526e671438019b6ba55827127d53fe77830053d96456935aabf9a4ebf77a8b819d7'+ 'ce8bf2acba824bb3bd400b13744498b65e295fc4dd586a7306ddcd53e41c8b14435d4ca0319bc956868a1fbd6b7ecf062379ba925a2a0f356b7e13e11159a512'+ '02d447669047ee1a94430633614c7eaa5f582dc80581464635b2beb36d418e6318937369aa3a1b3d59f36ccee62b6520abd55092c8ef49dd9e7a0950230a114e') # Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable # Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array withScan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-18 00:03:42 | LOW | 2 |
| 2026-08-17 00:18:29 | LOW | 2 |
| 2026-08-16 00:03:42 | LOW | 2 |
| 2026-08-15 00:26:13 | LOW | 2 |
| 2026-08-14 00:03:41 | LOW | 2 |
| 2026-08-13 00:17:07 | LOW | 2 |
| 2026-08-12 00:27:08 | LOW | 2 |
| 2026-08-11 23:21:47 | LOW | 2 |
| 2026-07-22 00:29:32 | CLEAN | 2 |
| 2026-07-21 21:18:19 | LOW | 1 |
| 2026-07-17 00:06:16 | CLEAN | 2 |
| 2026-07-16 21:52:49 | LOW | 1 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |
| 2026-07-14 00:09:48 | LOW | 2 |
| 2026-07-13 00:19:36 | LOW | 2 |
| 2026-07-12 00:27:26 | LOW | 2 |
| 2026-07-11 00:25:18 | LOW | 2 |
| 2026-07-10 00:20:30 | LOW | 2 |
| 2026-07-09 00:22:38 | LOW | 2 |