flux-explorer

LOW
maintainer zefarie 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The npx tauri build command is used to build the project from its own source code, which is downloaded from the project's official GitHub repository; this is a standard part of the build process for Tauri applications and does not execute arbitrary remote code.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx tauri build command is used to build the project from its own source code, which is downloaded from the project's official GitHub repository; this is a standard part of the build process for Tauri applications and does not execute arbitrary remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:17 npx tauri build --bundles none

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zefarie <zefarie@users.noreply.github.com>
2pkgname=flux-explorer
3pkgver=0.2.0
4pkgrel=1
5pkgdesc="Lightweight file explorer built with Tauri v2 and Rust for Linux"
6arch=('x86_64')
7url="https://github.com/zefarie/flux-explorer"
8license=('MIT')
9depends=('webkit2gtk-4.1' 'gtk3' 'ffmpeg' 'poppler')
10makedepends=('rust' 'cargo' 'nodejs' 'npm' 'pkgconf')
11source=("$pkgname-$pkgver.tar.gz::https://github.com/zefarie/$pkgname/archive/v$pkgver.tar.gz")
12sha256sums=('SKIP')
13
14build() {
15 cd "$pkgname-$pkgver"
16 npm install
17 npx tauri build --bundles none
18}
19
20package() {
21 cd "$pkgname-$pkgver"
22 install -Dm755 "src-tauri/target/release/$pkgname" "$pkgdir/usr/bin/$pkgname"
23 install -Dm644 "flux-explorer.desktop" "$pkgdir/usr/share/applications/$pkgname.desktop"
24 install -Dm644 "src-tauri/icons/icon.svg" "$pkgdir/usr/share/icons/hicolor/scalable/apps/$pkgname.svg"
25 for size in 32 128 256 512; do
26 install -Dm644 "src-tauri/icons/${size}x${size}.png" \
27 "$pkgdir/usr/share/icons/hicolor/${size}x${size}/apps/$pkgname.png"
28 done
29}
30

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion