gnome-shell-extension-randomwallpaper
The npx tsc command compiles TypeScript source code from the project's own repository using a standard development tool; this is a normal part of building the extension and does not execute untrusted remote code.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx tsc command compiles TypeScript source code from the project's own repository using a standard development tool; this is a normal part of building the extension and does not execute untrusted remote code.
1 higher static finding superseded - not the current verdict (shown for transparency)
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:33
npx tsc
PKGBUILD
1 offending line(s) highlighted# Maintainer: Mario Finelli <mario at finel dot li>
# Contributor: Igor Dyatlov <dyatlov.igor@protonmail.com>
pkgname=gnome-shell-extension-randomwallpaper
pkgver=3.2.0
pkgrel=1
pkgdesc="Random Wallpapers for Gnome 3"
arch=(any)
url=https://github.com/ifl0w/RandomWallpaperGnome3
license=(MIT)
depends=(gnome-shell)
makedepends=(blueprint-compiler git npm)
source=("RandomWallpaperGnome3::git+${url}.git#tag=v${pkgver}")
sha256sums=('ac621610da7d82f93439df72cfb0b89ce37f473520274cf5b6534f9fe6407088')
prepare() {
cd RandomWallpaperGnome3
npm ci
}
build() {
cd RandomWallpaperGnome3
local uuid="$(grep -Po '(?<="uuid": ")[^"]*' src/metadata.json)"
local schema=$(grep -Po '(?<="settings-schema": ")[^"]*' \
src/metadata.json).gschema.xml
mkdir "$uuid"
# UI
blueprint-compiler batch-compile "$uuid/ui" src/ui src/ui/*.blp
# JS
npx tsc
# schemas
mkdir "$uuid/schemas"
glib-compile-schemas --targetdir="$uuid/schemas" src/schemas
# static files
cp "src/schemas/$schema" "$uuid/schemas"
cp src/metadata.json "$uuid"
cp src/stylesheet.css "$uuid"
# pack into zip
local extra_source=()
for file in "$uuid"/*; do
extra_source+=("--extra-source=$file")
done
gnome-extensions pack "${extra_source[@]}" "$uuid"
}
package() {
cd RandomWallpaperGnome3
local uuid="$(grep -Po '(?<="uuid": ")[^"]*' src/metadata.json)"
local schema=$(grep -Po '(?<="settings-schema": ")[^"]*' \
src/metadata.json).gschema.xml
local destdir="${pkgdir}/usr/share/gnome-shell/extensions/${uuid}"
install -dm0755 "$destdir"
bsdtar xvf ${uuid}.shell-extension.zip -C "$destdir/" --no-same-owner
install -Dm0644 "$destdir/schemas/$schema" \
-t "$pkgdir/usr/share/glib-2.0/schemas/"
install -Dm0644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
# gnome-extensions pack doesn't seem to include the extra-source options
# no matter what I try, so we'll just manually add them to the package now...
cd "$uuid"
find ui -type f -name '*.ui' -exec install -Dm0644 {} -t "$destdir/ui/" \;
for s in adapter manager ui; do
find $s -type f -name '*.js' -exec install -Dm0644 {} -t "$destdir/$s/" \;
done
for js in *.js; do
[[ $js == extension.js ]] && continue
[[ $js == prefs.js ]] && continue
install -Dm0644 $js -t "$destdir/"
done
rm -rf "${destdir}/schemas"
}
# vim: set ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |