gpk-git

LOW
maintainer thann 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The npm install is part of building the project from its own source in the git repository, which is normal for AUR packages and not a supply-chain risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The npm install is part of building the project from its own source in the git repository, which is normal for AUR packages and not a supply-chain risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:28 npm install -g --prefix "$pkgdir"/usr --user root --unsafe-perm --production

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Jonathan Knapp <jaknapp8+aur@gmail.com>
2# Contributor: Braydon Fuller
3# URL: https://github.com/braydonf/gpk
4# Upstream: https://github.com/braydonf/gpk
5
6_pkgname=gpk
7pkgname=gpk-git
8pkgver=2.0.4
9pkgrel=1
10pkgdesc='A decentralized and secure package manager for nodejs.'
11arch=('i686' 'x86_64')
12url='https://github.com/braydonf/gpk'
13license=('APACHE')
14depends=('nodejs' 'python2' 'git')
15#makedepends=('gcc' 'make')
16provides=('gpk')
17conflicts=('gpk')
18source=("$pkgname::git+https://github.com/braydonf/gpk.git")
19md5sums=('SKIP')
20
21pkgver() {
22 cd $pkgname
23 git describe | sed 's/^v//;s/-/./g'
24}
25
26package() {
27 cd "$pkgname"
28 npm install -g --prefix "$pkgdir"/usr --user root --unsafe-perm --production
29 install -D -m644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
30 chmod -R 755 "$pkgdir"/usr/bin
31 #HACK: npm is being lame and only installing a symlink =/
32 rm "$pkgdir/usr/lib/node_modules/$_pkgname"
33 find * -exec install -D -m644 "{}" "$pkgdir/usr/lib/node_modules/$_pkgname/{}" \;
34 find "$pkgdir/usr/lib/node_modules/$_pkgname" -exec chmod +x "{}" \;
35
36 #HACK: remove references to $srcdir & $pkgdir (if you care)
37 # npm install -g removeNPMAbsolutePaths --prefix "$pkgdir"/usr
38 # "$pkgdir"/usr/bin/removeNPMAbsolutePaths "$pkgdir"/usr
39 # npm uninstall -g removeNPMAbsolutePaths --prefix "$pkgdir"/usr
40}
41

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion