electron-gpt-git
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The PKGBUILD clones the upstream source directly from the official GitHub repository and runs 'npm install' against it. The npmmirror.com registry substitution is conditional on the build machine being geolocated in China (via ipinfo.io), which is a common and well-known pattern in AUR packages targeting Chinese users. npmmirror.com is the official Alibaba/Taobao npm mirror widely used in China and mirrors the official npm registry — it is not a personal or rogue host. The package-lock.json is present in the upstream source, so dependency versions are pinned. The ELECTRON_SKIP_BINARY_DOWNLOAD=1 and system electron usage avoid downloading pre-built Electron binaries. The curl to ipinfo.io during build is a minor privacy/reproducibility concern but not a security threat. Overall this is a standard Electron app build pattern with a legitimate CN mirror fallback; the cheaper model's concern is a false positive on a recognized official mirror. The risk is low (sloppy geolocation check, non-reproducible builds) rather than a genuine supply-chain threat.
1 higher static finding superseded - not the current verdict (shown for transparency)
npm_install_external
Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.
-
PKGBUILD:82
NODE_ENV=development npm add -D @electron-forge/plugin-local-electron
PKGBUILD
1 offending line(s) highlighted# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
pkgname=electron-gpt-git
pkgver=r1417.09f2c72
_electronversion=33
_nodeversion=20
pkgrel=1
pkgdesc="Simplified chat using OpenAI's GPT.(Use system-wide electron)"
arch=('any')
url="https://github.com/Bubuclem/electron-gpt"
license=('CC0-1.0')
depends=(
"electron${_electronversion}"
'python'
'python-setuptools'
'nodejs'
)
makedepends=(
'npm'
'git'
'gendesk'
'nvm'
'curl'
)
source=(
"${pkgname%-git}.git::git+${url}.git"
"${pkgname%-git}.sh"
)
options=(
'!strip'
'!emptydirs'
)
sha256sums=('SKIP'
'291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
pkgver() {
cd "${srcdir}/${pkgname%-git}.git"
set -o pipefail
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
}
_ensure_local_nvm() {
local NVM_DIR="${srcdir}/.nvm"
source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
nvm install "${_nodeversion}"
nvm use "${_nodeversion}"
}
prepare() {
cd "${srcdir}/${pkgname%-git}.git"
sed -i -e "
s/@electronversion@/${_electronversion}/g
s/@appname@/${pkgname%-git}/g
s/@runname@/app/g
s/@cfgdirname@/${pkgname%-git}/g
s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
" "${srcdir}/${pkgname%-git}.sh"
_ensure_local_nvm
gendesk -q -f -n \
--pkgname="${pkgname%-git}" \
--pkgdesc="${pkgdesc}" \
--name="${pkgname%-git}" \
--categories="Utility" \
--exec="${pkgname%-git} %U"
export ELECTRON_SKIP_BINARY_DOWNLOAD=1
export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
HOME="${srcdir}/.electron-gyp"
{
echo -e '\n'
#echo 'build_from_source=true'
echo "cache=${srcdir}/.npm_cache"
echo "maxsockets=10"
} >> .npmrc
if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
{
echo 'registry=https://registry.npmmirror.com'
echo 'electron_mirror=https://registry.npmmirror.com/-/binary/electron/'
echo 'electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/'
} >> .npmrc
find ./ -type f -name "package-lock.json" -exec sed -i "s/registry.npmjs.org/registry.npmmirror.com/g" {} +
fi
sed -i "s/\.ico/\.png/g" main.js
sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
NODE_ENV=development npm install --legacy-peer-deps
NODE_ENV=development npm add -D @electron-forge/plugin-local-electron
}
build() {
cd "${srcdir}/${pkgname%-git}.git"
local electronDist="/usr/lib/electron${_electronversion}"
sed -i -e "
3i\ plugins: [
3i\ {
3i\ name: '@electron-forge/plugin-local-electron',
3i\ config: {
3i\ electronPath: \'${electronDist}\'
3i\ }
3i\ }
3i\ ],
" forge.config.js
NODE_ENV=production npm run package
}
package() {
install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
install -Dm755 -d "${pkgdir}/usr/lib/${pkgname%-git}"
cp -Pr --no-preserve=ownership "${srcdir}/${pkgname%-git}.git/out/chatgpt-linux-"*/resources/app "${pkgdir}/usr/lib/${pkgname%-git}"
install -Dm644 "${srcdir}/${pkgname%-git}.git/LICENSE.md" -t "${pkgdir}/usr/share/licenses/${pkgname}"
install -Dm644 "${srcdir}/${pkgname%-git}.git/assets/favicon.png" "${pkgdir}/usr/share/pixmaps/${pkgname%-git}.png"
install -Dm644 "${srcdir}/${pkgname%-git}.git/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |