face-unlock-bin

LOW
maintainer Felitendo 0 votes scanned 2026-09-28 15:21:17.813621
View on AUR
Why flagged

The package installs a prebuilt binary from the project's own GitHub releases, which is a normal distribution method for AUR packages; the low severity is due to few votes and recent upload, not inherent risk.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt binary from the project's own GitHub releases, which is a normal distribution method for AUR packages; the low severity is due to few votes and recent upload, not inherent risk.

PKGBUILD

1# Maintainer: Felitendo
2# This PKGBUILD is updated automatically:
3# https://github.com/Felitendo/PKGBUILDS
4
5pkgname=face-unlock-bin
6pkgver=2.1.0
7pkgrel=1
8pkgdesc="Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary)"
9arch=('x86_64')
10url="https://github.com/LoonixTools/face-unlock"
11# The program is GPL, the two face networks are MIT (YuNet) and Apache-2.0
12# (SFace). The daemon has OpenCV (Apache-2.0) linked in, with its copies of
13# protobuf, libjpeg-turbo, libpng and zlib. All texts are in the package.
14license=('GPL-3.0-or-later' 'MIT' 'Apache-2.0' 'BSD-3-Clause' 'IJG' 'Zlib' 'libpng-2.0')
15# What the binaries load, plus what the face-unlock command runs. No opencv:
16# it is linked in.
17depends=('bash' 'coreutils' 'gawk' 'grep' 'sed' 'gettext' 'systemd' 'systemd-libs' 'pam' 'polkit'
18 'qt6-base' 'qt6-declarative' 'qt6-wayland' 'wayland' 'layer-shell-qt' 'ki18n'
19 'glibc' 'libgcc' 'libstdc++' 'hicolor-icon-theme')
20optdepends=('hyprpolkitagent: password windows on Hyprland and Niri')
21provides=('face-unlock')
22conflicts=('face-unlock' 'plasma-face-unlock')
23install="${pkgname}.install"
24options=('!debug')
25# Upstream's release workflow builds this tarball on Arch: the make install
26# tree of face-unlock, in one folder. The agent uses Qt's private API, so it
27# fits the Qt that Arch had at the release.
28_tarball="face-unlock-${pkgver}-arch-${CARCH}.tar.zst"
29source=("${_tarball}::${url}/releases/download/v${pkgver}/${_tarball}")
30noextract=("${_tarball}")
31sha256sums=('b3b48a2c40650cc00ecbde713b86275fe8aef4885ba005c1de6d040974555393')
32
33package() {
34 # extracted here and not by makepkg, so the files keep the root owner
35 # the tarball gives them
36 bsdtar -xpf "$srcdir/${_tarball}" -C "$pkgdir" --strip-components 1
37 mv "$pkgdir/usr/share/licenses/face-unlock" "$pkgdir/usr/share/licenses/$pkgname"
38}
39

Scan history

Scanned at (UTC)SeverityRules
2026-09-28 15:21:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion