gpk-git
The npm install is part of building the project from its own source in the git repository, which is normal for AUR packages and not a supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The npm install is part of building the project from its own source in the git repository, which is normal for AUR packages and not a supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
npm_install_external
Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.
-
PKGBUILD:28
npm install -g --prefix "$pkgdir"/usr --user root --unsafe-perm --production
PKGBUILD
1 offending line(s) highlighted# Maintainer: Jonathan Knapp <jaknapp8+aur@gmail.com>
# Contributor: Braydon Fuller
# URL: https://github.com/braydonf/gpk
# Upstream: https://github.com/braydonf/gpk
_pkgname=gpk
pkgname=gpk-git
pkgver=2.0.4
pkgrel=1
pkgdesc='A decentralized and secure package manager for nodejs.'
arch=('i686' 'x86_64')
url='https://github.com/braydonf/gpk'
license=('APACHE')
depends=('nodejs' 'python2' 'git')
#makedepends=('gcc' 'make')
provides=('gpk')
conflicts=('gpk')
source=("$pkgname::git+https://github.com/braydonf/gpk.git")
md5sums=('SKIP')
pkgver() {
cd $pkgname
git describe | sed 's/^v//;s/-/./g'
}
package() {
cd "$pkgname"
npm install -g --prefix "$pkgdir"/usr --user root --unsafe-perm --production
install -D -m644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
chmod -R 755 "$pkgdir"/usr/bin
#HACK: npm is being lame and only installing a symlink =/
rm "$pkgdir/usr/lib/node_modules/$_pkgname"
find * -exec install -D -m644 "{}" "$pkgdir/usr/lib/node_modules/$_pkgname/{}" \;
find "$pkgdir/usr/lib/node_modules/$_pkgname" -exec chmod +x "{}" \;
#HACK: remove references to $srcdir & $pkgdir (if you care)
# npm install -g removeNPMAbsolutePaths --prefix "$pkgdir"/usr
# "$pkgdir"/usr/bin/removeNPMAbsolutePaths "$pkgdir"/usr
# npm uninstall -g removeNPMAbsolutePaths --prefix "$pkgdir"/usr
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |