f1multiviewer-bin
maintainer extremtechniker
· 17 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a prebuilt Electron app from the project's own release infrastructure (releases.multiviewer.app), which is plausibly official; the binary is not obfuscated or executed remotely, and the host, while not on a standard whitelist, is project-specific and checksummed.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt Electron app from the project's own release infrastructure (releases.multiviewer.app), which is plausibly official; the binary is not obfuscated or executed remotely, and the host, while not on a standard whitelist, is project-specific and checksummed.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=("https://releases.multiviewer.app/download/$_build/MultiViewer-linux-x64-$pkgver.zip"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: AntiCompositeNumber <anticompositenumber+aur@gmail.com>
2
# Maintainer: ExtremTechniker <aur@extremtechniker.io>
3
pkgname=f1multiviewer-bin
4
pkgver=2.8.2
5
# This ID changes for every release, you must grab it from https://multiviewer.app/download each time.
6
_build=488393778
7
pkgrel=1
8
pkgdesc="Unofficial motorsports desktop client"
9
arch=('x86_64')
10
url="https://multiviewer.app"
11
license=('unknown') # Licenses in the dist apply to Electron, not f1multiviewer
12
depends=('nss' 'alsa-lib' 'gtk3' 'at-spi2-core' 'xdg-utils')
13
makedepends=('asar')
14
provides=('f1multiviewer')
15
conflicts=('f1multiviewer')
16
install=f1multiviewer-bin.install
17
source=("https://releases.multiviewer.app/download/$_build/MultiViewer-linux-x64-$pkgver.zip"
18
"f1multiviewer.desktop")
19
noextract=()
20
sha256sums=('3671357b5ab8543f493174f7b017c03b569ca60dd7ac29e7b1668f76012cd9a3'
21
'00dd9ca8d94a729b80125f6f9ee2287ccd3f86975338c5ce1d12575130d73a6a')
22
23
package() {
24
install -d "$pkgdir/opt/$pkgname"
25
cp -a "MultiViewer-linux-x64/." "$pkgdir/opt/$pkgname"
26
chmod 755 "$pkgdir/opt/$pkgname"
27
chmod 755 "$pkgdir/opt/$pkgname/multiviewer"
28
29
install -d "$pkgdir/usr/bin/"
30
ln -s "/opt/$pkgname/multiviewer" "$pkgdir/usr/bin/f1multiviewer"
31
ln -s "/opt/$pkgname/multiviewer" "$pkgdir/usr/bin/multiviewer"
32
33
asar extract-file "MultiViewer-linux-x64/resources/app.asar" ".webpack/main/88a36af69fdc182ce561a66de78de7b1.png"
34
install -Dm644 "88a36af69fdc182ce561a66de78de7b1.png" "$pkgdir/usr/share/pixmaps/f1multiviewer.png"
35
install -Dm644 f1multiviewer.desktop "$pkgdir/usr/share/applications/f1multiviewer.desktop"
36
37
install -Dm644 "MultiViewer-linux-x64/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/Electron-LICENSE"
38
install -Dm644 "MultiViewer-linux-x64/LICENSES.chromium.html" "$pkgdir/usr/share/licenses/$pkgname/LICENSES.chromium.html"
39
}
40
Changes since previous scan
--- PKGBUILD @ 2026-07-26 00:07+++ PKGBUILD @ 2026-08-03 00:08@@ -1,9 +1,9 @@ # Maintainer: AntiCompositeNumber <anticompositenumber+aur@gmail.com> # Maintainer: ExtremTechniker <aur@extremtechniker.io> pkgname=f1multiviewer-bin-pkgver=2.8.1+pkgver=2.8.2 # This ID changes for every release, you must grab it from https://multiviewer.app/download each time.-_build=488375741+_build=488393778 pkgrel=1 pkgdesc="Unofficial motorsports desktop client" arch=('x86_64')@@ -17,7 +17,7 @@ source=("https://releases.multiviewer.app/download/$_build/MultiViewer-linux-x64-$pkgver.zip" "f1multiviewer.desktop") noextract=()-sha256sums=('572d3f59473df2da5662199d6b59b08f229804f220bae4c5b43d267e33a788b0'+sha256sums=('3671357b5ab8543f493174f7b017c03b569ca60dd7ac29e7b1668f76012cd9a3' '00dd9ca8d94a729b80125f6f9ee2287ccd3f86975338c5ce1d12575130d73a6a') package() {Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 05:31:42 | MEDIUM | 1 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 15:27:57 | MEDIUM | 2 |
| 2026-07-24 13:27:52 | MEDIUM | 1 |
| 2026-07-24 11:27:50 | MEDIUM | 1 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |