discord_arch_electron
The package downloads official Discord binaries from Discord's own infrastructure (dl.discordapp.net, stable.dl2.discordapp.net) to integrate with the system Electron; this is a legitimate repackaging for security/performance, not malicious code execution or supply-chain substitution.
Triggered rules
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads official Discord binaries from Discord's own infrastructure (dl.discordapp.net, stable.dl2.discordapp.net) to integrate with the system Electron; this is a legitimate repackaging for security/performance, not malicious code execution or supply-chain substitution.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:30
source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz" -
PKGBUILD:31
'LICENSE.html::https://discord.com/terms' -
PKGBUILD:37
"core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"
PKGBUILD
3 offending line(s) highlighted# Maintainer: Zoddo <archlinux+aur@zoddo.fr>
# Contributor: Thaodan <AUR+me@thaodan.de>
# Contributor: Manuel Hüsers <aur@huesers.de>
# Contributor: huyizheng
# Contributor: johnnyapol <arch@johnnyapol.me>
# Based off the discord community repo PKGBUILD by Filipe Laíns (FFY00) <lains@archlinux.org>
_pkgname=discord
_electron=electron
pkgname=${_pkgname}_arch_electron
pkgver=1.0.158
pkgrel=1
epoch=1
pkgdesc="Discord using system provided ${_electron} for increased security and performance"
arch=('x86_64')
provides=("${_pkgname}")
conflicts=("${_pkgname}")
url='https://discord.com'
license=('LicenseRef-custom')
options=('!strip')
install="$pkgname.install"
depends=("${_electron}" 'libxss')
makedepends=('asar'
'jq'
'python-pyelftools' # Required for Krisp patcher
'python-capstone') # Required for Krisp patcher
optdepends=('libpulse: Pulseaudio support'
'xdg-utils: Open files')
source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz"
'LICENSE.html::https://discord.com/terms'
'OSS-LICENSES.html::https://discord.com/licenses'
'discord-launcher.sh'
'krisp-patcher.py'
# Discord modules (from 'curl "https://updates.discord.com/distributions/app/manifests/latest?channel=stable&platform=linux&arch=x64"')
"core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"
"discord_desktop_core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_desktop_core/1/full.distro"
"discord_zstd-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_zstd/1/full.distro"
"discord_krisp-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_krisp/1/full.distro"
"discord_rpc-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_rpc/1/full.distro"
"discord_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_utils/1/full.distro"
"discord_voice-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_voice/1/full.distro"
"discord_game_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_game_utils/1/full.distro"
"discord_erlpack-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_erlpack/1/full.distro"
"discord_modules-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_modules/1/full.distro"
"discord_spellcheck-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_spellcheck/1/full.distro"
"discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro"
"discord_cloudsync-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_cloudsync/1/full.distro"
"discord_sysimg-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_sysimg/1/full.distro")
sha512sums=('a05e3bddb4d48597ae4d56a23b2b8f8c095b853a3658e95c2a62dffedfab93b2d4f3dbd646ee3f1a8796edabb1af2c2c7fcd8ef1b0fe26ecd67e1eaa6b624f18'
'2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec'
'5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05'
'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1'
'85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'
'f7e4a07a277a139a0a240156b862523e68447c0360a2e252e51da74ebfaa3d50d599fc21980085342fef2e6d686570c4ea76c1941c76397ca84e849610b1d207'
'c66ae752a73451f5ded26fe9d46285c7c8d25b8c1224c65abf4e70a1a074fc3d1f348094a510f89a6cc996968e9c9476869c6db97bdfbc7c686f2d0e38474c5c'
'c48e5be6bea155191c5e294b286959d346fb0b557ca5638a90ac2b7aa4ed89ced5458d5b4627707fc0f4d7b0463410e79b8f347ddece28f18c4ed765b11c2db9'
'77d2ef853c8a28cfe63bc25d9145d98d71f877c30af63540d3bc9a3eb8b3b9f4559ca839f8f7b3865d8a5353240e7bb01302ac28d756f4e11ca57f79a37b02f6'
'4e2fcd4ea3d1053268a50977a7074065473e3add92e44ff2db6b3d914085640fefb3015885674e9f9e6ddd9012ee0cf180337c3b7b0e65e90c21d5ecf0b47344'
'8f943cff82db3c244fc0e933c57a3ca9c62dbf3125ed42d9da49681478781b1fb02a551ef12f491e075da89815f185bfddf2043359e302dddf1a53550b642a7a'
'2b324b882705745587f760753807dfeb963de21968a35680fffe9160b5e81f7f14bd8c2f89b4014af05dda936522889fc2162f87a7e8975697f985ef601fbdb3'
'e047736044c5d3b5155118cc4bdbc96663a78b30eb10e741440b2f7563314a9403edec8a6fb2bc7fe65104dad8553ae656a59e284ba716f9b9af0bdb7920db8c'
'bbc1fae0094c6a1ba788db20d1aadca82fd1483e8c302767ee113330a7678f088a812a5e1aadfafd2eff9af42791dfb87a74d7d012fb676d52a640596c5c1429'
'7d5a8f89ea73f35f0824a9f03aa258ce6939e9cd6d0a5aa0415c6a63f474360e59579f23b4038342fab5dae3f41379f3f55c2db71b091e1db24422fcb0c1a8d8'
'0e1b67a3e8025b062d47fbc878511fa08e71502969bb0b22ff161ba9c6d7be44f4e86af6a0dfdf9fb419c014d4e4f916de68b597282e385910b4e6c97414b417'
'7e4ca73b41e1edbf193006e95c7c94218ac0f4c84c5e7220a9591e8e96a02a3ac2eb12bebbb2f034f5758147a50361cf8c2530178aa273c7c68ba89278eff8e7'
'18350a7170519e1a126406a814a1502c90328ca1ab1b8f5722db109c692449d27bb25a9c781d76fc47d359064375ec300c3723cb87a1cffa7cbc484952e33fe3'
'92362cf99e51aae87094a74488fe79f34786021faeed9c6666b423667e31c5011a655f8ad38c9440508abefc95c0ec7ab6e15577edb950db7fcf3b8472f2e460')
# Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable
# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with
# literal hashes, set them to SKIP with indexed assignments (pacman-contrib#119)
# https://gitlab.archlinux.org/pacman/pacman-contrib/-/issues/119
sha512sums[1]='SKIP'
sha512sums[2]='SKIP'
# Colored makepkg-like functions
_all_off="$(tput sgr0)"
_bold="${_all_off}$(tput bold)"
_blue="${_bold}$(tput setaf 4)"
_red="${_bold}$(tput setaf 1)"
msg_blue() {
printf "${_blue} ->${_bold} $1${_all_off}\n"
}
error() {
printf "${_blue}==>${_red} ERROR:${_bold} %s${_all_off}\n" "$1" >&2
exit 1
}
prepare() {
msg_blue "Extracting core-${pkgver}.tar.br"
tar -xf core-${pkgver}.tar.br --use-compress-program=brotli --one-top-level=core --strip-components=1 files/
for module in discord_*.tar.br; do
msg_blue "Extracting ${module}"
tar -xf "${module}" --use-compress-program=brotli --one-top-level="modules/${module%%-*}" --strip-components=1 files/
done
# prepare launcher script
sed -i -e "s|@PKGNAME@|${_pkgname}|" \
-e "s|@ELECTRON@|${_electron}|" \
discord-launcher.sh
# fix the .desktop file
sed -i -e "s|Exec=.*|Exec=/usr/bin/${_pkgname}|" ${_pkgname^}/$_pkgname.desktop
}
build() {
msg_blue 'Patching app.asar to use system electron'
asar e core/resources/app.asar core/resources/app
rm core/resources/app.asar
sed -i \
-e "s|^Exec=\${exePath}$|Exec=/usr/bin/${_pkgname}|" \
-e "s|^Name=\${appName}$|Name=${_pkgname^}|" \
-e "s|^Icon=\${iconPath}$|Icon=${_pkgname}|" \
-e "s|resourcesPath=path_1\.default\.join(require\.main\.filename,\"\.\.\",\"\.\.\"),|resourcesPath='/usr/share/${_pkgname}/resources',|" \
-e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|g" \
core/resources/app/bundle.js
sed -i -e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|" core/resources/app/splashScreenPreload.js
# This is required to properly show the window icon under wayland
jq ".desktopName = \"${_pkgname}.desktop\"" core/resources/app/package.json > tmp.json
mv tmp.json core/resources/app/package.json
asar p core/resources/app core/resources/app.asar
rm -rf core/resources/app
# Set the newUpdater key to false in build_info.json in order to disable the new Discord updater (released on 2026-05-04, version 1.0.136),
# Also add a localModulesRoot key that points to the Discord modules we're packaging.
jq ".newUpdater = false | .localModulesRoot = \"/usr/share/${_pkgname}/modules\"" core/resources/build_info.json > tmp.json
mv tmp.json core/resources/build_info.json
msg_blue 'Patching Krisp to run with system electron'
# original: https://github.com/sersorrel/sys/blob/main/hm/discord/krisp-patcher.py
python krisp-patcher.py "modules/discord_krisp/discord_krisp.node" \
|| error 'Krisp patcher failed. You can comment it out in the PKGBUILD, but Krisp will not work.'
# Krisp fails to initialize if this directory is not present (or if can't be created). Logs:
# [MediaEngineStore] Failed to load Krisp module: Failed to setup Krisp module, error code: -4
# [AVError] AV error reported: noise-canceller-error {"underlyingError":"NoiseCancellerError.KRISP_INIT_ERROR_GLOBAL_INIT"}
mkdir -p "modules/discord_krisp/KMS/logs"
}
package() {
# create necessary directories
install -d "${pkgdir}/usr/share/${_pkgname}"
# copy relevant data
cp -r core/resources/ "${pkgdir}/usr/share/${_pkgname}/"
cp -r modules/ "${pkgdir}/usr/share/${_pkgname}/"
# intall icon and desktop file
install -Dm 644 ${_pkgname^}/$_pkgname.png "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png"
install -Dm 644 ${_pkgname^}/$_pkgname.desktop "${pkgdir}/usr/share/applications/${_pkgname}.desktop"
# install the launch script
install -Dm 755 discord-launcher.sh "${pkgdir}/usr/bin/${_pkgname}"
# install licenses
install -Dm 644 LICENSE.html "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.html"
install -Dm 644 OSS-LICENSES.html "${pkgdir}/usr/share/licenses/${pkgname}/OSS-LICENSES.html"
}
Changes since previous scan
--- PKGBUILD @ 2026-09-21 00:26+++ PKGBUILD @ 2026-10-02 00:00@@ -9,7 +9,7 @@ _pkgname=discord _electron=electron pkgname=${_pkgname}_arch_electron-pkgver=1.0.157+pkgver=1.0.158 pkgrel=1 epoch=1 pkgdesc="Discord using system provided ${_electron} for increased security and performance"@@ -48,25 +48,25 @@ "discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro" "discord_cloudsync-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_cloudsync/1/full.distro" "discord_sysimg-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_sysimg/1/full.distro")-sha512sums=('dc96d21e010b2929068c58d41e8a22954bbb4c70e4bb9c09b9b54c6398c5d1c1fc895b32fa848b861cf3751a7be6a90e7a898c93c4be57295d3f3e43d9261fa6'+sha512sums=('a05e3bddb4d48597ae4d56a23b2b8f8c095b853a3658e95c2a62dffedfab93b2d4f3dbd646ee3f1a8796edabb1af2c2c7fcd8ef1b0fe26ecd67e1eaa6b624f18' '2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec' '5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05' 'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1' '85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'- 'ee49bca40ca1d2489536ba1c8169c6af8e0475c320be11c6ce5f9fc6fd59ad1fc675911c39bc7c9484a2ca79873c9b5ea08988668dd77db6732d6e90a858a76c'- '3001d91cf81a46fbf827cda0fb9fd36a89551e08269f9e34d1d57cbbccf18eec8e1f434e3e94fb4a270027903485f4c8fbd434380ce37f9aa284ef270e0cc78e'- 'aef19ce9c59a0cd965d022b26efa14c675d8d9f566155537db46e846234645129896076e62f69afaa89e4e53fe6eb0e3489fa1e83295c15839b2c94e385a0dde'- 'a91e3240ef308fb081a68f87f8689f09a7ab8b295f1a6db05dbea3030c29b23863c2a9955249f971dc7703c365e5b6fccbdf6b9f3e5edb6f8aaec246da7794fa'- '495d450183b6039fa38c0427b1dc4acdf8d925157621e41e03d265e3ccaa40278aec15decc8b43ab4a96e176338b1e9628ad99ea8d7d70abf8aef1edaf4005e8'- '997446283554df96d4a09bceff705c86606170425421ae3f7d6a21be271b971971e39ea631b2a3bb6caf9bf372a628ba6b92820db466d4b25ae94ae7c526c91f'- 'e954cfd4199490d779de622ea7721fe7b4c63ce879f662ac2ba0cd3c1cbbe68380ee8bc3dd4a0f3a405ec24ff0e7be5fad56126a44af0f13b1c6ac1af869ffae'- 'b89aeb60f86d31483e9d23e43f2b4376e7725d3c2284eacfc9298f821a3afa2718f01bc60a12c0a154f2424536632109336c81074766a377172289ed56f0f1a6'- 'df4ccd0c13dbe5a088ed22b8431f5a49a60dce22950a6d3a3c17eead40c8e9ef02e795aaee7a548e9e5e63c5bce5f25f01faaffd92428b169393fe19cb872d39'- 'aef89cb3f2741c5749a63ebed0fc8194cbbedef651fe2f393fe789a123c5682ad678ebca50eca7a2c21e724714c561e6af74598481d4197d5ea48f7cfa2ee650'- '4fa0c362e87456a2f34d822ddec99c86a61df3599b1d1c53a12f965143e4c8d517e367f4f5405703f14e8d3ce9f29d7f93e8bf036d517711a6ab7f1a1c021df6'- '03402851bcd373c038a2c063dc33d25372f6bb04e7198c47ae8343f80e3947dd89f79d467a83760b9d54b6e463d782526ccc0018a11d57ced94907a8d989abd5'- 'c2e02ac28992e82bd3e68da00424a21f21bfbb6094d26347e25aa0756ad9c40fc4fef885f172e3a2c0b9e101ceb56757d5bcf4624cccab4cadcbd83fe4597bf0'- '59058457fc18912bf7f4d7c3bfadd89f748304f430a4d745fd70d723fab6bc5c56a8e11ea527ff6684688846bc17cf1f892d9b785f7dabd034581f25e99e84c7')+ 'f7e4a07a277a139a0a240156b862523e68447c0360a2e252e51da74ebfaa3d50d599fc21980085342fef2e6d686570c4ea76c1941c76397ca84e849610b1d207'+ 'c66ae752a73451f5ded26fe9d46285c7c8d25b8c1224c65abf4e70a1a074fc3d1f348094a510f89a6cc996968e9c9476869c6db97bdfbc7c686f2d0e38474c5c'+ 'c48e5be6bea155191c5e294b286959d346fb0b557ca5638a90ac2b7aa4ed89ced5458d5b4627707fc0f4d7b0463410e79b8f347ddece28f18c4ed765b11c2db9'+ '77d2ef853c8a28cfe63bc25d9145d98d71f877c30af63540d3bc9a3eb8b3b9f4559ca839f8f7b3865d8a5353240e7bb01302ac28d756f4e11ca57f79a37b02f6'+ '4e2fcd4ea3d1053268a50977a7074065473e3add92e44ff2db6b3d914085640fefb3015885674e9f9e6ddd9012ee0cf180337c3b7b0e65e90c21d5ecf0b47344'+ '8f943cff82db3c244fc0e933c57a3ca9c62dbf3125ed42d9da49681478781b1fb02a551ef12f491e075da89815f185bfddf2043359e302dddf1a53550b642a7a'+ '2b324b882705745587f760753807dfeb963de21968a35680fffe9160b5e81f7f14bd8c2f89b4014af05dda936522889fc2162f87a7e8975697f985ef601fbdb3'+ 'e047736044c5d3b5155118cc4bdbc96663a78b30eb10e741440b2f7563314a9403edec8a6fb2bc7fe65104dad8553ae656a59e284ba716f9b9af0bdb7920db8c'+ 'bbc1fae0094c6a1ba788db20d1aadca82fd1483e8c302767ee113330a7678f088a812a5e1aadfafd2eff9af42791dfb87a74d7d012fb676d52a640596c5c1429'+ '7d5a8f89ea73f35f0824a9f03aa258ce6939e9cd6d0a5aa0415c6a63f474360e59579f23b4038342fab5dae3f41379f3f55c2db71b091e1db24422fcb0c1a8d8'+ '0e1b67a3e8025b062d47fbc878511fa08e71502969bb0b22ff161ba9c6d7be44f4e86af6a0dfdf9fb419c014d4e4f916de68b597282e385910b4e6c97414b417'+ '7e4ca73b41e1edbf193006e95c7c94218ac0f4c84c5e7220a9591e8e96a02a3ac2eb12bebbb2f034f5758147a50361cf8c2530178aa273c7c68ba89278eff8e7'+ '18350a7170519e1a126406a814a1502c90328ca1ab1b8f5722db109c692449d27bb25a9c781d76fc47d359064375ec300c3723cb87a1cffa7cbc484952e33fe3'+ '92362cf99e51aae87094a74488fe79f34786021faeed9c6666b423667e31c5011a655f8ad38c9440508abefc95c0ec7ab6e15577edb950db7fcf3b8472f2e460') # Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable # Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array withScan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 19:35:51 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 21:26:26 | Low | 2 |
| 2026-09-13 00:19:54 | Clean | 2 |
| 2026-09-12 11:11:46 | Low | 1 |
| 2026-09-12 00:25:17 | Low | 2 |