fluxer-bin-domainchoose

LOW
maintainer BlackCherry 0 votes scanned 2026-09-28 17:23:17.479743
View on AUR
Why flagged

Downloads prebuilt Electron binaries from api.fluxer.app, which appears to be the project's own official API/CDN endpoint (matching the declared url=https://fluxer.app), with pinned sha256 checksums for both architectures; no obfuscation, exfiltration, or redirection to unrelated third-party hosts detected.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Downloads prebuilt Electron binaries from api.fluxer.app, which appears to be the project's own official API/CDN endpoint (matching the declared url=https://fluxer.app), with pinned sha256 checksums for both architectures; no obfuscation, exfiltration, or redirection to unrelated third-party hosts detected.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source_x86_64=("fluxer-${pkgver}-x64.tar.gz::https://api.fluxer.app/dl/desktop/stable/linux/x64/${pkgver}/tar_gz")

PKGBUILD

1 offending line(s) highlighted
1pkgname=fluxer-bin-domainchoose
2pkgver=2026.927.142044
3pkgrel=3
4pkgdesc="Fluxer Desktop Application (gives you the ability to change the domain)"
5arch=('x86_64' 'aarch64')
6url="https://fluxer.app"
7license=('AGPL-3.0-only')
8depends=('gtk3' 'nss' 'alsa-lib' 'nodejs' 'zenity')
9provides=('fluxer')
10conflicts=('fluxer')
11options=('!strip')
12
13source=("fluxer.desktop" "fluxer-wrapper.sh")
14sha256sums=('981daa8015b823fef254bb8e79fe6b28f77dda02cdc374796443bd64f5041de1'
15 'fb60cdb156e0a3ac03611ed451a9665a1935377354f70acf33a55332c4a758ea')
16
17source_x86_64=("fluxer-${pkgver}-x64.tar.gz::https://api.fluxer.app/dl/desktop/stable/linux/x64/${pkgver}/tar_gz")
18sha256sums_x86_64=('126dbef18f4cad1cdc930fd469b059d82b09d10f6493ea8c9dbbfe5861364c82')
19
20source_aarch64=("fluxer-${pkgver}-arm64.tar.gz::https://api.fluxer.app/dl/desktop/stable/linux/arm64/${pkgver}/tar_gz")
21sha256sums_aarch64=('d6e40b0ee5b6adf6cbdba7c14748c2f409d5644166ed08815af6393f0900e140')
22
23package() {
24 local _dir
25 case "$CARCH" in
26 x86_64) _dir="Fluxer-${pkgver}-linux-x64" ;;
27 aarch64) _dir="Fluxer-${pkgver}-linux-arm64" ;;
28 esac
29 if [ ! -d "$srcdir/$_dir" ]; then
30 _dir=$(cd "$srcdir" && ls -d [Ff]luxer*"${pkgver}"*/ 2>/dev/null | head -n1)
31 _dir="${_dir%/}"
32 fi
33 if [ -z "$_dir" ] || [ ! -d "$srcdir/$_dir" ]; then
34 echo "Error: could not find extracted directory for $CARCH" >&2
35 return 1
36 fi
37
38 install -d "$pkgdir/opt/fluxer"
39 cp -a "$srcdir/$_dir/." "$pkgdir/opt/fluxer/"
40
41 # Wrapper
42 install -Dm755 "$srcdir/fluxer-wrapper.sh" "$pkgdir/usr/bin/fluxer"
43
44 install -Dm644 "$srcdir/fluxer.desktop" "$pkgdir/usr/share/applications/fluxer.desktop"
45 install -dm777 "$pkgdir/opt/fluxer/resources"
46 install -Dm666 /dev/null "$pkgdir/etc/fluxer.conf"
47
48 local _icon _size _found=0
49 for _icon in "$srcdir/$_dir"/resources/icons/[0-9]*x[0-9]*.png; do
50 [ -f "$_icon" ] || continue
51 _size="$(basename "$_icon" .png)"
52 install -Dm644 "$_icon" \
53 "$pkgdir/usr/share/icons/hicolor/$_size/apps/fluxer.png"
54 _found=1
55 done
56 if [ "$_found" -eq 0 ]; then
57 echo "Error: no icons" >&2
58 return 1
59 fi
60}
61

Scan history

Scanned at (UTC)SeverityRules
2026-09-28 17:23:17 Low 3
2026-09-28 17:21:20 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion