ember-p2p-bin

LOW
maintainer robertfoster 0 votes scanned 2026-10-09 00:05:33.126700
View on AUR
Why flagged

The package downloads a prebuilt .deb from the project's official GitHub releases, which is then extracted and installed; while using a binary release carries some supply-chain risk, it is from the legitimate project source and not actively malicious, and the rest of the PKGBUILD follows standard, safe practices.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads a prebuilt .deb from the project's official GitHub releases, which is then extracted and installed; while using a binary release carries some supply-chain risk, it is from the legitimate project source and not actively malicious, and the rest of the PKGBUILD follows standard, safe practices.

PKGBUILD

1# Maintainer: robertfoster
2pkgname=ember-p2p-bin
3_pkgname=ember
4_appname=Ember
5pkgver=1.7.2 # renovate: datasource=github-releases depName=untaimed18/Ember-P2P
6pkgrel=1
7pkgdesc="Modern eMule KAD client built with Rust and Tauri"
8arch=('x86_64')
9url="https://github.com/untaimed18/Ember-P2P"
10license=('GPL-3.0-only')
11depends=('cairo' 'dbus' 'gdk-pixbuf2' 'glib2' 'glibc' 'gtk3' 'hicolor-icon-theme'
12 'libgcc' 'libsoup3' 'webkit2gtk-4.1'
13 'libayatana-appindicator') # dlopen()ed for the tray icon
14optdepends=('xdg-utils: open folders and links from the app')
15provides=("${_pkgname}-p2p")
16conflicts=("${_pkgname}-p2p")
17options=('!debug')
18source=("LICENSE-${pkgver}::https://raw.githubusercontent.com/untaimed18/Ember-P2P/v${pkgver}/LICENSE")
19source_x86_64=("${url}/releases/download/v${pkgver}/${_appname}_${pkgver}_amd64.deb")
20noextract=("${_appname}_${pkgver}_amd64.deb")
21
22prepare() {
23 mkdir -p "${srcdir}/deb"
24 bsdtar -xOf "${srcdir}/${_appname}_${pkgver}_amd64.deb" 'data.tar.*' |
25 bsdtar -xf - -C "${srcdir}/deb"
26
27 # add the missing trailing ';' to MimeType so desktop-file-validate is happy
28 sed -i '/^MimeType=/s/[^;]$/&;/' \
29 "${srcdir}/deb/usr/share/applications/${_appname}.desktop"
30}
31
32package() {
33 cd "${srcdir}/deb/usr"
34
35 install -Dm755 -t "${pkgdir}/usr/bin" "bin/${_pkgname}"
36
37 # bundled resources (GeoIP database) looked up by tauri under /usr/lib/Ember
38 install -Dm644 -t "${pkgdir}/usr/lib/${_appname}/resources" \
39 "lib/${_appname}/resources/dbip-country-lite.mmdb"
40 install -Dm644 -t "${pkgdir}/usr/lib/${_appname}/icons" \
41 "lib/${_appname}/icons/icon.ico"
42
43 install -Dm644 -t "${pkgdir}/usr/share/applications" \
44 "share/applications/${_appname}.desktop"
45 install -Dm644 -t "${pkgdir}/usr/share/mime/packages" \
46 "share/mime/packages/${_pkgname}.xml"
47
48 # tauri drops the 128x128@2x icon into a non-standard "256x256@2" directory
49 local _size
50 for _size in 32x32 128x128 512x512; do
51 install -Dm644 -t "${pkgdir}/usr/share/icons/hicolor/${_size}/apps" \
52 "share/icons/hicolor/${_size}/apps/${_pkgname}.png"
53 done
54 install -Dm644 -t "${pkgdir}/usr/share/icons/hicolor/256x256/apps" \
55 "share/icons/hicolor/256x256@2/apps/${_pkgname}.png"
56
57 install -Dm644 "${srcdir}/LICENSE-${pkgver}" \
58 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
59}
60
61sha256sums=('3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986')
62sha256sums_x86_64=('5c14c2aa885f497373116b9f6e54667a601f7f75213678c56e78f917632ac9ef')
63

Scan history

Scanned at (UTC)SeverityRules
2026-10-09 00:05:33 Low 2
2026-10-08 22:09:59 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion