f1multiviewer-bin
The package downloads a prebuilt Electron app from the project's own release infrastructure (releases.multiviewer.app), which is plausibly official; the binary is not executed during build, and the worst case of a swapped source is running malicious code in a desktop app, but the host is specific to the project and not a generic file host.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt Electron app from the project's own release infrastructure (releases.multiviewer.app), which is plausibly official; the binary is not executed during build, and the worst case of a swapped source is running malicious code in a desktop app, but the host is specific to the project and not a generic file host.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=("https://releases.multiviewer.app/download/$_build/MultiViewer-linux-x64-$pkgver.zip"
PKGBUILD
1 offending line(s) highlighted# Maintainer: AntiCompositeNumber <anticompositenumber+aur@gmail.com>
# Maintainer: ExtremTechniker <aur@extremtechniker.io>
pkgname=f1multiviewer-bin
pkgver=2.8.4
# This ID changes for every release, you must grab it from https://multiviewer.app/download each time.
_build=518116301
pkgrel=1
pkgdesc="Unofficial motorsports desktop client"
arch=('x86_64')
url="https://multiviewer.app"
license=('unknown') # Licenses in the dist apply to Electron, not f1multiviewer
depends=('nss' 'alsa-lib' 'gtk3' 'at-spi2-core' 'xdg-utils')
makedepends=('asar')
provides=('f1multiviewer')
conflicts=('f1multiviewer')
install=f1multiviewer-bin.install
source=("https://releases.multiviewer.app/download/$_build/MultiViewer-linux-x64-$pkgver.zip"
"f1multiviewer.desktop")
noextract=()
sha256sums=('212359a4ce4dcfd4d86f6ccfdc4d75ee54d02387eeba61d969c5cd70760a3474'
'00dd9ca8d94a729b80125f6f9ee2287ccd3f86975338c5ce1d12575130d73a6a')
package() {
install -d "$pkgdir/opt/$pkgname"
cp -a "MultiViewer-linux-x64/." "$pkgdir/opt/$pkgname"
chmod 755 "$pkgdir/opt/$pkgname"
chmod 755 "$pkgdir/opt/$pkgname/multiviewer"
install -d "$pkgdir/usr/bin/"
ln -s "/opt/$pkgname/multiviewer" "$pkgdir/usr/bin/f1multiviewer"
ln -s "/opt/$pkgname/multiviewer" "$pkgdir/usr/bin/multiviewer"
asar extract-file "MultiViewer-linux-x64/resources/app.asar" ".webpack/main/88a36af69fdc182ce561a66de78de7b1.png"
install -Dm644 "88a36af69fdc182ce561a66de78de7b1.png" "$pkgdir/usr/share/pixmaps/f1multiviewer.png"
install -Dm644 f1multiviewer.desktop "$pkgdir/usr/share/applications/f1multiviewer.desktop"
install -Dm644 "MultiViewer-linux-x64/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/Electron-LICENSE"
install -Dm644 "MultiViewer-linux-x64/LICENSES.chromium.html" "$pkgdir/usr/share/licenses/$pkgname/LICENSES.chromium.html"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |