face-unlock-bin
LOW
maintainer Felitendo
0 votes
scanned 2026-09-28 15:21:17.813621
Why flagged
The package installs a prebuilt binary from the project's own GitHub releases, which is a normal distribution method for AUR packages; the low severity is due to few votes and recent upload, not inherent risk.
Triggered rules
Low
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
Low
AI review
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt binary from the project's own GitHub releases, which is a normal distribution method for AUR packages; the low severity is due to few votes and recent upload, not inherent risk.
PKGBUILD
1
# Maintainer: Felitendo
2
# This PKGBUILD is updated automatically:
3
# https://github.com/Felitendo/PKGBUILDS
4
5
pkgname=face-unlock-bin
6
pkgver=2.1.0
7
pkgrel=1
8
pkgdesc="Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary)"
9
arch=('x86_64')
10
url="https://github.com/LoonixTools/face-unlock"
11
# The program is GPL, the two face networks are MIT (YuNet) and Apache-2.0
12
# (SFace). The daemon has OpenCV (Apache-2.0) linked in, with its copies of
13
# protobuf, libjpeg-turbo, libpng and zlib. All texts are in the package.
14
license=('GPL-3.0-or-later' 'MIT' 'Apache-2.0' 'BSD-3-Clause' 'IJG' 'Zlib' 'libpng-2.0')
15
# What the binaries load, plus what the face-unlock command runs. No opencv:
16
# it is linked in.
17
depends=('bash' 'coreutils' 'gawk' 'grep' 'sed' 'gettext' 'systemd' 'systemd-libs' 'pam' 'polkit'
18
'qt6-base' 'qt6-declarative' 'qt6-wayland' 'wayland' 'layer-shell-qt' 'ki18n'
19
'glibc' 'libgcc' 'libstdc++' 'hicolor-icon-theme')
20
optdepends=('hyprpolkitagent: password windows on Hyprland and Niri')
21
provides=('face-unlock')
22
conflicts=('face-unlock' 'plasma-face-unlock')
23
install="${pkgname}.install"
24
options=('!debug')
25
# Upstream's release workflow builds this tarball on Arch: the make install
26
# tree of face-unlock, in one folder. The agent uses Qt's private API, so it
27
# fits the Qt that Arch had at the release.
28
_tarball="face-unlock-${pkgver}-arch-${CARCH}.tar.zst"
29
source=("${_tarball}::${url}/releases/download/v${pkgver}/${_tarball}")
30
noextract=("${_tarball}")
31
sha256sums=('b3b48a2c40650cc00ecbde713b86275fe8aef4885ba005c1de6d040974555393')
32
33
package() {
34
# extracted here and not by makepkg, so the files keep the root owner
35
# the tarball gives them
36
bsdtar -xpf "$srcdir/${_tarball}" -C "$pkgdir" --strip-components 1
37
mv "$pkgdir/usr/share/licenses/face-unlock" "$pkgdir/usr/share/licenses/$pkgname"
38
}
39
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-28 15:21:17 | Low | 2 |