ipfs-desktop
The package downloads a WebUI CAR file from a trustless gateway for IPFS, which is a legitimate use of decentralized content addressing; the source is verified via checksum and CID matching, and the content is static assets, not executable code, posing minimal risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a WebUI CAR file from a trustless gateway for IPFS, which is a legitimate use of decentralized content addressing; the source is verified via checksum and CID matching, and the content is static assets, not executable code, posing minimal risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:38
"webui-${_webui_cid}.car::https://trustless-gateway.link/ipfs/${_webui_cid}?format=car"
PKGBUILD
1 offending line(s) highlighted# Maintainer: @RubenKelevra <rubenkelevra@gmail.com>
# Contributor: Alex Henrie <alexhenrie24@gmail.com>
_electron_pkg='electron44'
_webui_cid='bafybeiciqeyipumpmhxzlxnbqdbbv6u5uij4hy4wax64dmj7kvrhusiq6y'
pkgname='ipfs-desktop'
pkgver='0.50.1'
pkgrel=3
epoch=1
pkgdesc='Desktop client for the InterPlanetary File System'
arch=('x86_64')
url="https://github.com/ipfs/${pkgname}"
license=(
'0BSD'
'Apache-2.0'
'BSD-2-Clause'
'BSD-3-Clause'
'BlueOak-1.0.0'
'ISC'
'MIT'
'OFL-1.1'
'Python-2.0'
)
replaces=('ipfs-desktop-electron')
depends=(
"${_electron_pkg}"
'kubo>=0.43.1'
'libappindicator'
)
makedepends=(
'asar'
'nodejs'
'npm'
)
source=(
"${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/v${pkgver}.tar.gz"
"webui-${_webui_cid}.car::https://trustless-gateway.link/ipfs/${_webui_cid}?format=car"
"${pkgname}.desktop"
"${pkgname}-startup.sh"
'Inter-LICENSE.txt::https://raw.githubusercontent.com/rsms/inter/3ac1bd32a473ea60d40d8f444820247e96dd7e70/LICENSE.txt'
'Montserrat-OFL.txt::https://raw.githubusercontent.com/JulietaUla/Montserrat/fc12e6819947c76db917f9d589a1d327e37a7b6b/OFL.txt'
)
b2sums=(
'a58496e1bde4c28f64a6b97eed27a35c156e8c328485f6c950f9cd1772c3647d960d8972c63a824c88dfe31da4e3360352e93712589cd172a07da51595e37733'
'49e1e7d4d55325d4ea05561a4ff4c64537988e5e841231a95d59328fc9f9b60f3098185bf757b70c42d2175f8a2b6394a0f2a9377df7d1603d69edbd4c3655ec'
'849d57fd59653ed0c6eca01769ad12a01f37f6a5316f1a83c0bf7cae576074b978e3ca555d50a56114d177e5fe4817338106698716f054a3e18ae1c81d7a8785'
'bb51f22c1cf58020bbb9d7f9dde2bfd6f838443130d89539c9ce2474f5a1987b332f63dd21b8a903880a77f96d58e8a868d0468e15d266357bdfe3409380eab2'
'5417464983de312c9c2a250c64281d82c17fd531f78ceccaa44d97c6999a3faf61324eaaf588240a9d0f9319bb302b7d7ed88bdbc55c188efd0357645190690a'
'93047b82ab53aa80f1db73e4f9d0d2b2ac30fcee1be00b2b43c63a63da1ec41b32935acca720ed4b31d3cfd0e57d61faaf79be4951a90fa973312ab22e4f1488'
)
_pkgsrc="${pkgname}-${pkgver}"
_electron_env() {
local _version_file="/usr/lib/${_electron_pkg}/version"
[[ -r "${_version_file}" ]] || {
printf 'Missing Electron version file: %s\n' "${_version_file}" >&2
return 1
}
SYSTEM_ELECTRON_VERSION=$(<"${_version_file}")
[[ -n "${SYSTEM_ELECTRON_VERSION}" ]] || {
printf 'Electron version file is empty: %s\n' "${_version_file}" >&2
return 1
}
export SYSTEM_ELECTRON_VERSION
}
_warn_if_electron_outdated() {
local _installed _latest_local _vf _v
[[ -r "/usr/lib/${_electron_pkg}/version" ]] || return 0
_installed=$(< "/usr/lib/${_electron_pkg}/version")
_latest_local=$_installed
shopt -s nullglob
for _vf in /usr/lib/electron*/version; do
_v=$(< "$_vf")
if [[ "$(printf '%s\n%s\n' "$_latest_local" "$_v" | sort -V | tail -n1)" != "$_latest_local" ]]; then
_latest_local=$_v
fi
done
shopt -u nullglob
if [[ $_installed != "$_latest_local" ]]; then
echo "==> WARNING: Packaging uses not the latest major version of electron installed. ${_electron_pkg} ${_installed} is used, but a newer local Electron version (${_latest_local}) is available on the system." >&2
fi
}
prepare() (
local _car_path
local _expected_webui_cid
local _ipfs_path
local _kubo_version
local _webui_path="${srcdir}/webui-${_webui_cid}"
cd -- "${_pkgsrc}" || return 1
_expected_webui_cid=$(
sed -nE \
'/"build:webui:download"/s/.*[[:space:]]-c[[:space:]]+([^[:space:]\"]+).*/\1/p' \
package.json
)
[[ -n "${_expected_webui_cid}" ]] || {
printf '%s\n' 'Unable to determine the WebUI CID expected by upstream' >&2
return 1
}
[[ "${_webui_cid}" == "${_expected_webui_cid}" ]] || {
printf 'WebUI CID mismatch: PKGBUILD has %s, upstream expects %s\n' \
"${_webui_cid}" "${_expected_webui_cid}" >&2
printf 'Update _webui_cid and its source checksum before building.\n' >&2
return 1
}
_ipfs_path=$(mktemp -d --tmpdir "${pkgname}-kubo.XXXXXXXX") || return 1
trap 'rm -rf -- "${_ipfs_path}"' EXIT
_car_path=$(readlink -f -- "${srcdir}/webui-${_webui_cid}.car")
[[ -f "${_car_path}" ]] || {
printf 'WebUI CAR is missing: %s\n' "${_car_path}" >&2
return 1
}
IPFS_PATH="${_ipfs_path}" ipfs init --profile=server >/dev/null
IPFS_PATH="${_ipfs_path}" ipfs dag import "${_car_path}" >/dev/null
rm -rf -- "${_webui_path}"
IPFS_PATH="${_ipfs_path}" ipfs get "/ipfs/${_webui_cid}" -o "${_webui_path}"
[[ -f "${_webui_path}/index.html" ]] || {
printf 'Materialized WebUI is missing index.html: %s\n' "${_webui_path}" >&2
return 1
}
_kubo_version=$(sed -nE 's/^[[:space:]]*"kubo":[[:space:]]*"([^"]+)".*/\1/p' package.json)
[[ -n "${_kubo_version}" ]] || {
printf '%s\n' 'Unable to determine the bundled Kubo version' >&2
return 1
}
npm pkg set "allowScripts[kubo@${_kubo_version}]=false" --json
npm ci --no-audit --no-fund \
2> >(sed '/glob@11\.1\.0: Old versions of glob are not supported/d' >&2)
[[ ! -e node_modules/kubo/kubo/ipfs ]] || {
printf '%s\n' 'Unexpected bundled Kubo binary found after npm install' >&2
return 1
}
)
build() {
local -a _builder_options
_warn_if_electron_outdated
_electron_env
cd -- "${_pkgsrc}" || return 1
IPFS_WEBUI_PATH="${srcdir}/webui-${_webui_cid}" \
npm_config_offline=true npm run build
_builder_options=(
"-c.electronDist=/usr/lib/${_electron_pkg}"
"-c.electronVersion=${SYSTEM_ELECTRON_VERSION}"
)
npm_config_offline=true npm exec -- electron-builder --linux --dir --publish never \
"${_builder_options[@]}"
}
package() {
local _license
local _packaged_app="${srcdir}/${pkgname}-packaged-app"
mkdir -p -- "${pkgdir}/usr/lib/${pkgname}"
cp -a -- "${_pkgsrc}/dist/linux-unpacked/resources/." "${pkgdir}/usr/lib/${pkgname}/"
rm -rf -- "${_packaged_app}"
asar extract "${_pkgsrc}/dist/linux-unpacked/resources/app.asar" "${_packaged_app}"
[[ -d "${_packaged_app}/node_modules" ]] || {
printf '%s\n' 'Packaged application is missing node_modules' >&2
return 1
}
[[ -d "${_packaged_app}/assets/webui/static/js" ]] || {
printf '%s\n' 'Packaged application is missing WebUI JavaScript assets' >&2
return 1
}
install -Dm644 -- "${_pkgsrc}/assets/webui/ipfs-logo-512-ice.png" \
"${pkgdir}/usr/share/pixmaps/${pkgname}.png"
install -Dm644 -- "${_pkgsrc}/LICENSE" \
"${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
for _license in 'Inter-LICENSE.txt' 'Montserrat-OFL.txt'; do
install -Dm644 -- "${srcdir}/${_license}" \
"${pkgdir}/usr/share/licenses/${pkgname}/webui/${_license}"
done
while IFS= read -r -d '' _license; do
install -Dm644 -- "${_license}" \
"${pkgdir}/usr/share/licenses/${pkgname}/${_license#"${_packaged_app}/"}"
done < <(find "${_packaged_app}/node_modules" -type f \
\( -iname 'license*' -o -iname 'copying*' -o -iname 'notice*' \) -print0)
while IFS= read -r -d '' _license; do
install -Dm644 -- "${_license}" \
"${pkgdir}/usr/share/licenses/${pkgname}/webui/${_license##*/}"
done < <(find "${_packaged_app}/assets/webui/static/js" -maxdepth 1 -type f \
-name '*.LICENSE.txt' -print0)
sed "s|@ELECTRON_PKG@|${_electron_pkg}|" \
"${srcdir}/${pkgname}-startup.sh" \
| install -Dm755 /dev/stdin "${pkgdir}/usr/bin/${pkgname}"
install -Dm644 -- "${srcdir}/${pkgname}.desktop" \
"${pkgdir}/usr/share/applications/${pkgname}.desktop"
chmod -R u+rwX,go+rX,go-w -- "${pkgdir}"
}
Changes since previous scan
--- PKGBUILD @ 2026-09-28 00:28+++ PKGBUILD @ 2026-10-02 00:00@@ -6,7 +6,7 @@ pkgname='ipfs-desktop' pkgver='0.50.1'-pkgrel=2+pkgrel=3 epoch=1 pkgdesc='Desktop client for the InterPlanetary File System' arch=('x86_64')@@ -26,6 +26,7 @@ depends=( "${_electron_pkg}" 'kubo>=0.43.1'+ 'libappindicator' ) makedepends=( 'asar'Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 17:21:20 | Medium | 1 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 21:44:41 | Medium | 1 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 07:39:45 | Medium | 1 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |