dlnacast-git

maintainer orphaned · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The npm install runs during packaging from the project's own source checkout, not from an external untrusted registry or host, so it is part of the normal build process for a Node.js application.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npm install runs during packaging from the project's own source checkout, not from an external untrusted registry or host, so it is part of the normal build process for a Node.js application.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:24 npm install --user root -g --prefix="$pkgdir/usr"

PKGBUILD

1 offending line(s) highlighted
1pkgname=dlnacast-git
2pkgver=r14.4b9f8a3
3pkgrel=1
4pkgdesc="A commandline UPnP/DLNA caster"
5arch=('any')
6makedepends=('git')
7url="https://github.com/xat/dlnacast"
8license=('MIT')
9depends=('nodejs' 'npm')
10source=($pkgname::git://github.com/xat/dlnacast.git)
11md5sums=(SKIP)
12
13pkgver() {
14 cd "$pkgname"
15 ( set -o pipefail
16 git describe --long 2>/dev/null | sed 's/\([^-]*-g\)/r\1/;s/-/./g' ||
17 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
18 )
19}
20
21package() {
22 cd $pkgname
23 mkdir -p $pkgdir/usr
24 npm install --user root -g --prefix="$pkgdir/usr"
25 cd $pkgdir
26 cd usr/lib/node_modules/
27 rm dlnacast
28 mv ../../../../../src/dlnacast-git dlnacast
29 cd dlnacast
30 install -D -m644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion