electrum-ltc-appimage
The package downloads a prebuilt AppImage from the project's official domain, which is used as-is and not executed during build; the source host is the official project site, so despite the static analyzer flag, the risk is low due to official origin and signature verification.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt AppImage from the project's official domain, which is used as-is and not executed during build; the source host is the official project site, so despite the static analyzer flag, the risk is low due to official origin and signature verification.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
source=("https://electrum-ltc.org/download/electrum-ltc-${pkgver}-x86_64.AppImage"
PKGBUILD
1 offending line(s) highlighted# Maintainer: VCalV
pkgname=electrum-ltc-appimage
pkgver=4.2.2.1
pkgrel=2
pkgdesc="Litecoin wallet (AppImage)"
arch=('x86_64')
url="https://electrum-ltc.org/"
license=('MIT')
depends=('fuse2' 'zlib' 'hicolor-icon-theme')
optdepends=('libxss: for screen saver suspension'
'gconf: for storing application preferences')
provides=('electrum-ltc')
conflicts=('electrum-ltc' 'electrum-ltc-git')
options=('!strip')
source=("https://electrum-ltc.org/download/electrum-ltc-${pkgver}-x86_64.AppImage"
"https://electrum-ltc.org/download/electrum-ltc-${pkgver}-x86_64.AppImage.asc")
# GPG key fingerprint for Electrum-LTC
validpgpkeys=('CAE1092AD3553FFD21C05DE36FC4C9F7F1BE8FEA')
sha256sums=('8c27621f87a51baf5b3a492696606a5b55c72b6a9804e3baa8f161cd7cc5d8f5'
'91719dd7b7b2f6e28766137a50430b755423d99bbc48876d9c73b67325574765')
prepare() {
# Make AppImage executable
chmod +x "electrum-ltc-${pkgver}-x86_64.AppImage"
}
package() {
# Install the AppImage
install -Dm755 "electrum-ltc-${pkgver}-x86_64.AppImage" \
"${pkgdir}/opt/electrum-ltc/electrum-ltc-${pkgver}-x86_64.AppImage"
# Create symlink in /usr/bin
install -dm755 "${pkgdir}/usr/bin"
ln -s "/opt/electrum-ltc/electrum-ltc-${pkgver}-x86_64.AppImage" \
"${pkgdir}/usr/bin/electrum-ltc"
# Extract desktop file and icon from AppImage
cd "${srcdir}"
./"electrum-ltc-${pkgver}-x86_64.AppImage" --appimage-extract electrum-ltc.desktop 2>/dev/null || true
./"electrum-ltc-${pkgver}-x86_64.AppImage" --appimage-extract electrum-ltc.png 2>/dev/null || true
# Install desktop file from AppImage
if [ -f "squashfs-root/electrum-ltc.desktop" ]; then
# Create directory first
install -dm755 "${pkgdir}/usr/share/applications"
# Modify the Exec line to use our symlink
sed 's|^Exec=.*|Exec=electrum-ltc %u|' "squashfs-root/electrum-ltc.desktop" > "${pkgdir}/usr/share/applications/electrum-ltc.desktop"
chmod 644 "${pkgdir}/usr/share/applications/electrum-ltc.desktop"
fi
# Install icon from AppImage
if [ -f "squashfs-root/electrum-ltc.png" ]; then
install -Dm644 "squashfs-root/electrum-ltc.png" \
"${pkgdir}/usr/share/pixmaps/electrum-ltc.png"
fi
# Clean up extracted files
rm -rf "squashfs-root" 2>/dev/null || true
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |