discord_arch_electron

maintainer Zoddo · 211 votes · scanned 2026-08-18 00:03:42.021799
LOW
View on AUR ↗
Why flagged The package downloads official Discord binaries from Discord's own infrastructure (discordapp.net, dl2.discordapp.net) which are plausibly the project's official sources; despite the static analyzer flagging non-standard hosts, these are legitimate release endpoints, and the package builds from verifiable upstream sources without executing untrusted remote code.

Triggered rules

LOW AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads official Discord binaries from Discord's own infrastructure (discordapp.net, dl2.discordapp.net) which are plausibly the project's official sources; despite the static analyzer flagging non-standard hosts, these are legitimate release endpoints, and the package builds from verifiable upstream sources without executing untrusted remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:30 source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz"
  • PKGBUILD:31 'LICENSE.html::https://discord.com/terms'
  • PKGBUILD:37 "core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"

PKGBUILD

3 offending line(s) highlighted
1# Maintainer: Zoddo <archlinux+aur@zoddo.fr>
2# Contributor: Thaodan <AUR+me@thaodan.de>
3# Contributor: Manuel Hüsers <aur@huesers.de>
4# Contributor: huyizheng
5# Contributor: johnnyapol <arch@johnnyapol.me>
6
7# Based off the discord community repo PKGBUILD by Filipe Laíns (FFY00) <lains@archlinux.org>
8
9_pkgname=discord
10_electron=electron
11pkgname=${_pkgname}_arch_electron
12pkgver=1.0.150
13pkgrel=1
14epoch=1
15pkgdesc="Discord using system provided ${_electron} for increased security and performance"
16arch=('x86_64')
17provides=("${_pkgname}")
18conflicts=("${_pkgname}")
19url='https://discord.com'
20license=('LicenseRef-custom')
21options=('!strip')
22install="$pkgname.install"
23depends=("${_electron}" 'libxss')
24makedepends=('asar'
25 'jq'
26 'python-pyelftools' # Required for Krisp patcher
27 'python-capstone') # Required for Krisp patcher
28optdepends=('libpulse: Pulseaudio support'
29 'xdg-utils: Open files')
30source=("https://dl.discordapp.net/apps/linux/${pkgver}/${_pkgname}-${pkgver}.tar.gz"
31 'LICENSE.html::https://discord.com/terms'
32 'OSS-LICENSES.html::https://discord.com/licenses'
33 'discord-launcher.sh'
34 'krisp-patcher.py'
35
36 # Discord modules (from 'curl "https://updates.discord.com/distributions/app/manifests/latest?channel=stable&platform=linux&arch=x64"')
37 "core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/full.distro"
38 "discord_desktop_core-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_desktop_core/1/full.distro"
39 "discord_zstd-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_zstd/1/full.distro"
40 "discord_krisp-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_krisp/1/full.distro"
41 "discord_rpc-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_rpc/1/full.distro"
42 "discord_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_utils/1/full.distro"
43 "discord_voice-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_voice/1/full.distro"
44 "discord_game_utils-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_game_utils/1/full.distro"
45 "discord_erlpack-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_erlpack/1/full.distro"
46 "discord_modules-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_modules/1/full.distro"
47 "discord_spellcheck-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_spellcheck/1/full.distro"
48 "discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro")
49sha512sums=('ef38c8c9dbdcecdb0d08202d5576ccfdfa7789b7bf3a5c5b41bffba3308ecd738a1285e89514407968aa1f59d0a3693582b3dd77c9b1e9891180365e32549b2c'
50 '2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec'
51 '5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05'
52 'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1'
53 '85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'
54 'f0a322304334265bc3ee1485eec718df70320a089992ac8c4c2802ce418e8d58d5b1fcf700ab98216f81512f5aeb4e29fedbf4dbddcc465ee90c9b815d4bc1e7'
55 'a96fbea3946631a63210812bb67e9921fdfc2c415e120e1919c1ec4880187b6cd9433668c5ca5fdbbfcc1c23c6a759995d734f0e9096baed4dea5da8eac9a536'
56 'a33345164429656bbcc28c48b6d82bf39ef622753686447199661ae2cb8a11780080db02a0a20d838a2dfb2625e4599478f8b16ea120c3ce250193f6133effd5'
57 '0464dada650407f44e7d3fd378e2fee36496dc898f25e2e486bb993d01afbc5233228b61ffa76a68ededba40887c91938d06c149280ca56e6c58790838d3a8e2'
58 '75fb9521399db1ffac32b97baa6ed09055b243a83a2b83864f8ba52060cc204b308305b7d917d3e2c78f7aaeaeed2ea23b927cc34d973446907ed4f403dbd75f'
59 'ceb6589cd74c06766d26311422d1522f88dbcb569d7c600c0d1e915404f19bf8d35c310d6c6aa1813477809e0de21c0fbc7a4a74eaafd31b2e50e16cded8fdb7'
60 'afa90192782ff0f7a03d9b0f0e3a53258ef7bb632ec991513c349d6b859cf26264f6cd1b9d54a96e9bc91afe1669bd849752aec22b5010c92cda0ef59e513ddd'
61 'c92c12100a5181309503c1ba2ffd41a9e9287b21645d86119ef823f1192958ee6cfa6fcce657647b8cfdc65cad8b767cce53cb3300c996875343fe2c1d1faa14'
62 '621291c04f248d69e9ae0022d84e6903b375e75598ea3198f787c94fd4efe1b944df42a9b8a6974ef5cdc18de3f7db03da26c73a7bf176f2d3524d6a298e3ea9'
63 '178f3b9089015712c7d487c3da340942b2b445cdb88c1e6f27579f25415b4526e671438019b6ba55827127d53fe77830053d96456935aabf9a4ebf77a8b819d7'
64 'ce8bf2acba824bb3bd400b13744498b65e295fc4dd586a7306ddcd53e41c8b14435d4ca0319bc956868a1fbd6b7ecf062379ba925a2a0f356b7e13e11159a512'
65 '02d447669047ee1a94430633614c7eaa5f582dc80581464635b2beb36d418e6318937369aa3a1b3d59f36ccee62b6520abd55092c8ef49dd9e7a0950230a114e')
66
67# Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable
68# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with
69# literal hashes, set them to SKIP with indexed assignments (pacman-contrib#119)
70# https://gitlab.archlinux.org/pacman/pacman-contrib/-/issues/119
71sha512sums[1]='SKIP'
72sha512sums[2]='SKIP'
73
74# Colored makepkg-like functions
75_all_off="$(tput sgr0)"
76_bold="${_all_off}$(tput bold)"
77_blue="${_bold}$(tput setaf 4)"
78_red="${_bold}$(tput setaf 1)"
79msg_blue() {
80 printf "${_blue} ->${_bold} $1${_all_off}\n"
81}
82error() {
83 printf "${_blue}==>${_red} ERROR:${_bold} %s${_all_off}\n" "$1" >&2
84 exit 1
85}
86
87prepare() {
88 msg_blue "Extracting core-${pkgver}.tar.br"
89 tar -xf core-${pkgver}.tar.br --use-compress-program=brotli --one-top-level=core --strip-components=1 files/
90
91 for module in discord_*.tar.br; do
92 msg_blue "Extracting ${module}"
93 tar -xf "${module}" --use-compress-program=brotli --one-top-level="modules/${module%%-*}" --strip-components=1 files/
94 done
95
96 # prepare launcher script
97 sed -i -e "s|@PKGNAME@|${_pkgname}|" \
98 -e "s|@ELECTRON@|${_electron}|" \
99 discord-launcher.sh
100
101 # fix the .desktop file
102 sed -i -e "s|Exec=.*|Exec=/usr/bin/${_pkgname}|" ${_pkgname^}/$_pkgname.desktop
103}
104
105build() {
106 msg_blue 'Patching app.asar to use system electron'
107
108 asar e core/resources/app.asar core/resources/app
109 rm core/resources/app.asar
110 sed -i \
111 -e "s|^Exec=\${exePath}$|Exec=/usr/bin/${_pkgname}|" \
112 -e "s|^Name=\${appName}$|Name=${_pkgname^}|" \
113 -e "s|^Icon=\${iconPath}$|Icon=${_pkgname}|" \
114 -e "s|resourcesPath=path_1\.default\.join(require\.main\.filename,\"\.\.\",\"\.\.\"),|resourcesPath='/usr/share/${_pkgname}/resources',|" \
115 -e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|g" \
116 core/resources/app/bundle.js
117 sed -i -e "s|process\.resourcesPath|'/usr/share/${_pkgname}/resources'|" core/resources/app/splashScreenPreload.js
118
119 # This is required to properly show the window icon under wayland
120 jq ".desktopName = \"${_pkgname}.desktop\"" core/resources/app/package.json > tmp.json
121 mv tmp.json core/resources/app/package.json
122
123 asar p core/resources/app core/resources/app.asar
124 rm -rf core/resources/app
125
126 # Set the newUpdater key to false in build_info.json in order to disable the new Discord updater (released on 2026-05-04, version 1.0.136),
127 # Also add a localModulesRoot key that points to the Discord modules we're packaging.
128 jq ".newUpdater = false | .localModulesRoot = \"/usr/share/${_pkgname}/modules\"" core/resources/build_info.json > tmp.json
129 mv tmp.json core/resources/build_info.json
130
131 msg_blue 'Patching Krisp to run with system electron'
132 # original: https://github.com/sersorrel/sys/blob/main/hm/discord/krisp-patcher.py
133 python krisp-patcher.py "modules/discord_krisp/discord_krisp.node" \
134 || error 'Krisp patcher failed. You can comment it out in the PKGBUILD, but Krisp will not work.'
135
136 # Krisp fails to initialize if this directory is not present (or if can't be created). Logs:
137 # [MediaEngineStore] Failed to load Krisp module: Failed to setup Krisp module, error code: -4
138 # [AVError] AV error reported: noise-canceller-error {"underlyingError":"NoiseCancellerError.KRISP_INIT_ERROR_GLOBAL_INIT"}
139 mkdir -p "modules/discord_krisp/KMS/logs"
140}
141
142package() {
143 # create necessary directories
144 install -d "${pkgdir}/usr/share/${_pkgname}"
145
146 # copy relevant data
147 cp -r core/resources/ "${pkgdir}/usr/share/${_pkgname}/"
148 cp -r modules/ "${pkgdir}/usr/share/${_pkgname}/"
149
150 # intall icon and desktop file
151 install -Dm 644 ${_pkgname^}/$_pkgname.png "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png"
152 install -Dm 644 ${_pkgname^}/$_pkgname.desktop "${pkgdir}/usr/share/applications/${_pkgname}.desktop"
153
154 # install the launch script
155 install -Dm 755 discord-launcher.sh "${pkgdir}/usr/bin/${_pkgname}"
156
157 # install licenses
158 install -Dm 644 LICENSE.html "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.html"
159 install -Dm 644 OSS-LICENSES.html "${pkgdir}/usr/share/licenses/${pkgname}/OSS-LICENSES.html"
160}
161

Changes since previous scan

--- PKGBUILD @ 2026-07-22 00:29
+++ PKGBUILD @ 2026-08-18 00:03
@@ -9,7 +9,7 @@
_pkgname=discord
_electron=electron
pkgname=${_pkgname}_arch_electron
-pkgver=1.0.149
+pkgver=1.0.150
pkgrel=1
epoch=1
pkgdesc="Discord using system provided ${_electron} for increased security and performance"
@@ -46,23 +46,23 @@
"discord_modules-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_modules/1/full.distro"
"discord_spellcheck-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_spellcheck/1/full.distro"
"discord_dispatch-${pkgver}.tar.br::https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/${pkgver}/discord_dispatch/1/full.distro")
-sha512sums=('07cec6aea9e36ffe7d786b55ea76f38e7469d14fc2c2d853686230f416f4e07886f02c883d929338d4b87c3d7a0b412f0e0da94f62f6b976d65a59dab759bff0'
+sha512sums=('ef38c8c9dbdcecdb0d08202d5576ccfdfa7789b7bf3a5c5b41bffba3308ecd738a1285e89514407968aa1f59d0a3693582b3dd77c9b1e9891180365e32549b2c'
'2590151db4404a9ecbae2c45269c74f5ea26479967de5bc0b221a9143f4efeeeda9e335c23cf1f982680ab4fd895dcf3fd5731bd230908b3b2568eee0ec223ec'
'5cccf397a772fed0db9b19253e496e78af27810227325ce681de985e2e0fbbdb195873d9642574ad3ae7bfcf4699bfdaa16933ca50c13cb98a1ff53c86c6de05'
'd5373e2b2e9754bdcdbcda81fc1392ce6605939651839868823f3c3e0bf16f6fba2fb73bc1a0ff230eebd743d1463f2e8b2295503248f14845b3a56e57385bd1'
'85da93530b2b92faad58cc84d0f7ddaea6b22fbec413e806c1981eb6369a301ec995eee6bfbe6b828e2cd0baf6168e578bbde456f2450a13199994ff9a1e7cd0'
- '8a630c3376cf7069f57ca22f2420e11a834c57be8a7016b9ae7125d4bd2a61b3456ba217b075e8554bfdfde3e4f59e4ff8758370641389c388af5a3383642c14'
- '21a12d18a330046d9d9dd7593be827b40baa4cf3915ce7968a279b43febb99c4c8a4134d2f26f3649cd991559fe155699cd5feb91bd97510bc2323de8d033bc2'
- '810c1219f3d008b945e75951d468d64aed2b342208c1eb9756374a880283a8a9984cf6bfa94e608fe48b3de8bdbf75f80789a1f6c1987637933e776b035b2a0a'
- '905e69d2af3615c80dd772d0096cb9a3773cfa42d4616f7f1709d78a4b0b8c9de19fd62d5c68943bd489fbb931aea593c1c5c67cf1c89c20d01b74158b963a81'
- 'f65e4f4b20eeac3b0efc958592fb184521b3c74d4ef95ebf12783bd057fa777ed1ff0c7b0a59369c50dc089a13f15d0799a461747d670fc37a171bb637b27ac8'
- '3d7410f8bdaad81563696eba0c185d187052289c29d8f23eed7067e9725e95cfa18d3ffd49c69431bf90bff943af63dcd1d823cfb0c8ee5f90a2ce8a752439c4'
- '11cea4c898b7290c73f3cc9aebfb4b115709487710cfe5a15843c9c21003714a57ade0440db680f44ae2ad202485e4ce302e99b44e20a4d3761b1d49b0f87192'
- 'e0f8c7c4b16d0ec39fa0e7b04954135568778e431f88aecc1292ec953a33278733f155ff876b2e4150c80894fadefbc99f8f0d7d7c6acf5cd093b098fb3be1bd'
- 'c3c48374265aa106301020463416133975536ad99e7c00e7617714270d9ee470b0143800216494fde14e2c2409322ee6dafed01497d68fda8af53f9f8ef29f23'
- '6e4e6c8d8d7338b88e3875a863b003472d46991b60f8df545a282efd0f09d0d6ddf53c813b5c394b42ce5d6bc489e6d3febb71e5d88a9bc0d623a467aef87416'
- '22a795896e538aa8065001acb0ea66363a879db672e8d72cea85dea4f516b68a341ef33b4516cf968f1215b17b7d434ae454ff55c94151a27086b87394460380'
- '802492d1d83dd3f197eb0e7a3fcde1f8b02a664d198729fc81b0c81a811bf29c2d0bfb7592a52f6e165efaaed9bdcea91a43000cb0d2bc16a8d63d62f06901f6')
+ 'f0a322304334265bc3ee1485eec718df70320a089992ac8c4c2802ce418e8d58d5b1fcf700ab98216f81512f5aeb4e29fedbf4dbddcc465ee90c9b815d4bc1e7'
+ 'a96fbea3946631a63210812bb67e9921fdfc2c415e120e1919c1ec4880187b6cd9433668c5ca5fdbbfcc1c23c6a759995d734f0e9096baed4dea5da8eac9a536'
+ 'a33345164429656bbcc28c48b6d82bf39ef622753686447199661ae2cb8a11780080db02a0a20d838a2dfb2625e4599478f8b16ea120c3ce250193f6133effd5'
+ '0464dada650407f44e7d3fd378e2fee36496dc898f25e2e486bb993d01afbc5233228b61ffa76a68ededba40887c91938d06c149280ca56e6c58790838d3a8e2'
+ '75fb9521399db1ffac32b97baa6ed09055b243a83a2b83864f8ba52060cc204b308305b7d917d3e2c78f7aaeaeed2ea23b927cc34d973446907ed4f403dbd75f'
+ 'ceb6589cd74c06766d26311422d1522f88dbcb569d7c600c0d1e915404f19bf8d35c310d6c6aa1813477809e0de21c0fbc7a4a74eaafd31b2e50e16cded8fdb7'
+ 'afa90192782ff0f7a03d9b0f0e3a53258ef7bb632ec991513c349d6b859cf26264f6cd1b9d54a96e9bc91afe1669bd849752aec22b5010c92cda0ef59e513ddd'
+ 'c92c12100a5181309503c1ba2ffd41a9e9287b21645d86119ef823f1192958ee6cfa6fcce657647b8cfdc65cad8b767cce53cb3300c996875343fe2c1d1faa14'
+ '621291c04f248d69e9ae0022d84e6903b375e75598ea3198f787c94fd4efe1b944df42a9b8a6974ef5cdc18de3f7db03da26c73a7bf176f2d3524d6a298e3ea9'
+ '178f3b9089015712c7d487c3da340942b2b445cdb88c1e6f27579f25415b4526e671438019b6ba55827127d53fe77830053d96456935aabf9a4ebf77a8b819d7'
+ 'ce8bf2acba824bb3bd400b13744498b65e295fc4dd586a7306ddcd53e41c8b14435d4ca0319bc956868a1fbd6b7ecf062379ba925a2a0f356b7e13e11159a512'
+ '02d447669047ee1a94430633614c7eaa5f582dc80581464635b2beb36d418e6318937369aa3a1b3d59f36ccee62b6520abd55092c8ef49dd9e7a0950230a114e')
# Skip "LICENSE.html" and "OSS-LICENSES.html" files hashes as they are unstable
# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with

Scan history

Scanned at (UTC)SeverityRules
2026-08-18 00:03:42 LOW 2
2026-08-17 00:18:29 LOW 2
2026-08-16 00:03:42 LOW 2
2026-08-15 00:26:13 LOW 2
2026-08-14 00:03:41 LOW 2
2026-08-13 00:17:07 LOW 2
2026-08-12 00:27:08 LOW 2
2026-08-11 23:21:47 LOW 2
2026-07-22 00:29:32 CLEAN 2
2026-07-21 21:18:19 LOW 1
2026-07-17 00:06:16 CLEAN 2
2026-07-16 21:52:49 LOW 1
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2
2026-07-14 00:09:48 LOW 2
2026-07-13 00:19:36 LOW 2
2026-07-12 00:27:26 LOW 2
2026-07-11 00:25:18 LOW 2
2026-07-10 00:20:30 LOW 2
2026-07-09 00:22:38 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion