footage-bin

MEDIUM
maintainer nvidiahater 0 votes scanned 2026-10-06 08:02:16.298752
View on AUR
Why flagged

The package extracts a prebuilt binary from Flathub's OSTree repository, modifies paths in-place, and installs it; while Flathub is a trusted source, the binary is not built locally and its modification via string replacement in a compiled binary introduces a supply-chain risk if the source were ever compromised.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 95%): The package extracts a prebuilt binary from Flathub's OSTree repository, modifies paths in-place, and installs it; while Flathub is a trusted source, the binary is not built locally and its modification via string replacement in a compiled binary introduces a supply-chain risk if the source were ever compromised.

PKGBUILD

1pkgname=footage-bin
2pkgver=1.4.0
3pkgrel=1
4pkgdesc="Trim, flip, rotate and crop videos using native Arch Linux libraries"
5arch=('x86_64')
6url="https://gitlab.com/adhami3310/Footage"
7license=('GPL-3.0-only')
8depends=(
9 'dconf'
10 'glib2'
11 'glibc'
12 'graphene'
13 'gst-editing-services'
14 'gst-libav'
15 'gst-plugin-gtk4'
16 'gst-plugins-bad'
17 'gst-plugins-base'
18 'gst-plugins-base-libs'
19 'gst-plugins-good'
20 'gst-plugins-ugly'
21 'gstreamer'
22 'gtk4'
23 'hicolor-icon-theme'
24 'libadwaita'
25 'libgcc'
26)
27makedepends=('ostree' 'perl')
28provides=("footage=${pkgver}")
29conflicts=('footage')
30options=('!debug')
31install=footage-bin.install
32
33# Update both commits when pkgver changes.
34# Pin the application and its matching translations to the Flathub 1.4.0 build.
35_commit='0aabb7e5bb04f9a4109c0826bddabeca0d36d0c02acc52889f24ca7a3ab26177'
36_locale_commit='2ac0c248c1371a510fc141b621c4ea59ad33050a8c80eb8e362bc436dcfe5316'
37
38prepare() {
39 local repo="${srcdir}/footage-repo"
40 local binary="${srcdir}/footage-flatpak/files/bin/footage"
41 local original_size
42 local version
43
44 ostree --repo="${repo}" init --mode=bare-user-only
45 ostree --repo="${repo}" remote add --force --no-gpg-verify \
46 flathub https://dl.flathub.org/repo/
47 ostree --repo="${repo}" pull --http-header='User-Agent=curl/8.20.0' \
48 flathub "${_commit}" "${_locale_commit}"
49 # Replace previous checkouts so prepare() can run again without stale files.
50 rm -rf "${srcdir}/footage-flatpak" "${srcdir}/footage-locale"
51 ostree --repo="${repo}" checkout --user-mode "${_commit}" "${srcdir}/footage-flatpak"
52 ostree --repo="${repo}" checkout --user-mode "${_locale_commit}" "${srcdir}/footage-locale"
53
54 version="$(sed -n 's/.*<release version="\([^"]*\)".*/\1/p' \
55 "${srcdir}/footage-flatpak/files/share/metainfo/io.gitlab.adhami3310.Footage.metainfo.xml" | head -n1)"
56 if [[ "${version}" != "${pkgver}" ]]; then
57 error 'Update the Flathub commits to match pkgver'
58 return 1
59 fi
60 if [[ "$(grep -aoF '/app/share/' "${binary}" | wc -l)" -ne 4 ]]; then
61 error 'Unexpected Footage resource path count'
62 return 1
63 fi
64 original_size="$(stat -c %s "${binary}")"
65 # Rust strings contain explicit lengths. Keep each replacement the same size.
66 perl -pi -e 's{/app/share/}{/usr/share/}g' "${binary}"
67 if [[ "$(stat -c %s "${binary}")" -ne "${original_size}" ]]; then
68 error 'The Footage path change modified the binary size'
69 return 1
70 fi
71}
72
73check() {
74 local appdir="${srcdir}/footage-flatpak/files"
75 local log="${srcdir}/footage-ldd.log"
76
77 if ! ldd -r "${appdir}/bin/footage" > "${log}"; then
78 cat "${log}"
79 return 1
80 fi
81 if grep -Eq 'not found|undefined symbol' "${log}"; then
82 cat "${log}"
83 return 1
84 fi
85 if grep -aFq '/app/' "${appdir}/bin/footage" || \
86 readelf -d "${appdir}/bin/footage" | grep -Eq '\((RPATH|RUNPATH)\)'; then
87 error 'Footage still contains a Flatpak path'
88 return 1
89 fi
90 glib-compile-schemas --strict --dry-run "${appdir}/share/glib-2.0/schemas"
91}
92
93package() {
94 local appdir="${srcdir}/footage-flatpak/files"
95 local directory
96 local translation
97 local language
98
99 install -Dm755 "${appdir}/bin/footage" "${pkgdir}/usr/bin/footage"
100 install -d "${pkgdir}/usr/share"
101 for directory in applications dbus-1 footage glib-2.0 icons metainfo; do
102 cp -a "${appdir}/share/${directory}" "${pkgdir}/usr/share/"
103 done
104 rm "${pkgdir}/usr/share/applications/mimeinfo.cache" \
105 "${pkgdir}/usr/share/glib-2.0/schemas/gschemas.compiled" \
106 "${pkgdir}/usr/share/icons/hicolor/icon-theme.cache"
107 sed -i 's#/app/bin/footage#/usr/bin/footage#' \
108 "${pkgdir}/usr/share/dbus-1/services/io.gitlab.adhami3310.Footage.service"
109
110 for translation in "${srcdir}/footage-locale/files/"*/share/*/LC_MESSAGES/footage.mo; do
111 language="${translation%/LC_MESSAGES/footage.mo}"
112 language="${language##*/}"
113 install -Dm644 "${translation}" \
114 "${pkgdir}/usr/share/locale/${language}/LC_MESSAGES/footage.mo"
115 done
116 install -Dm644 "${appdir}/share/licenses/io.gitlab.adhami3310.Footage/footage/COPYING" \
117 "${pkgdir}/usr/share/licenses/${pkgname}/COPYING"
118}
119

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 08:02:16 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion