ipfs-desktop

LOW
maintainer RubenKelevra 23 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads a WebUI CAR file from a trustless gateway for IPFS, which is a legitimate use of decentralized content addressing; the source is verified via checksum and CID matching, and the content is static assets, not executable code, posing minimal risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a WebUI CAR file from a trustless gateway for IPFS, which is a legitimate use of decentralized content addressing; the source is verified via checksum and CID matching, and the content is static assets, not executable code, posing minimal risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:38 "webui-${_webui_cid}.car::https://trustless-gateway.link/ipfs/${_webui_cid}?format=car"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: @RubenKelevra <rubenkelevra@gmail.com>
2# Contributor: Alex Henrie <alexhenrie24@gmail.com>
3
4_electron_pkg='electron44'
5_webui_cid='bafybeiciqeyipumpmhxzlxnbqdbbv6u5uij4hy4wax64dmj7kvrhusiq6y'
6
7pkgname='ipfs-desktop'
8pkgver='0.50.1'
9pkgrel=3
10epoch=1
11pkgdesc='Desktop client for the InterPlanetary File System'
12arch=('x86_64')
13url="https://github.com/ipfs/${pkgname}"
14license=(
15 '0BSD'
16 'Apache-2.0'
17 'BSD-2-Clause'
18 'BSD-3-Clause'
19 'BlueOak-1.0.0'
20 'ISC'
21 'MIT'
22 'OFL-1.1'
23 'Python-2.0'
24)
25replaces=('ipfs-desktop-electron')
26depends=(
27 "${_electron_pkg}"
28 'kubo>=0.43.1'
29 'libappindicator'
30)
31makedepends=(
32 'asar'
33 'nodejs'
34 'npm'
35)
36source=(
37 "${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/v${pkgver}.tar.gz"
38 "webui-${_webui_cid}.car::https://trustless-gateway.link/ipfs/${_webui_cid}?format=car"
39 "${pkgname}.desktop"
40 "${pkgname}-startup.sh"
41 'Inter-LICENSE.txt::https://raw.githubusercontent.com/rsms/inter/3ac1bd32a473ea60d40d8f444820247e96dd7e70/LICENSE.txt'
42 'Montserrat-OFL.txt::https://raw.githubusercontent.com/JulietaUla/Montserrat/fc12e6819947c76db917f9d589a1d327e37a7b6b/OFL.txt'
43)
44b2sums=(
45 'a58496e1bde4c28f64a6b97eed27a35c156e8c328485f6c950f9cd1772c3647d960d8972c63a824c88dfe31da4e3360352e93712589cd172a07da51595e37733'
46 '49e1e7d4d55325d4ea05561a4ff4c64537988e5e841231a95d59328fc9f9b60f3098185bf757b70c42d2175f8a2b6394a0f2a9377df7d1603d69edbd4c3655ec'
47 '849d57fd59653ed0c6eca01769ad12a01f37f6a5316f1a83c0bf7cae576074b978e3ca555d50a56114d177e5fe4817338106698716f054a3e18ae1c81d7a8785'
48 'bb51f22c1cf58020bbb9d7f9dde2bfd6f838443130d89539c9ce2474f5a1987b332f63dd21b8a903880a77f96d58e8a868d0468e15d266357bdfe3409380eab2'
49 '5417464983de312c9c2a250c64281d82c17fd531f78ceccaa44d97c6999a3faf61324eaaf588240a9d0f9319bb302b7d7ed88bdbc55c188efd0357645190690a'
50 '93047b82ab53aa80f1db73e4f9d0d2b2ac30fcee1be00b2b43c63a63da1ec41b32935acca720ed4b31d3cfd0e57d61faaf79be4951a90fa973312ab22e4f1488'
51)
52
53_pkgsrc="${pkgname}-${pkgver}"
54
55_electron_env() {
56 local _version_file="/usr/lib/${_electron_pkg}/version"
57
58 [[ -r "${_version_file}" ]] || {
59 printf 'Missing Electron version file: %s\n' "${_version_file}" >&2
60 return 1
61 }
62
63 SYSTEM_ELECTRON_VERSION=$(<"${_version_file}")
64 [[ -n "${SYSTEM_ELECTRON_VERSION}" ]] || {
65 printf 'Electron version file is empty: %s\n' "${_version_file}" >&2
66 return 1
67 }
68
69 export SYSTEM_ELECTRON_VERSION
70}
71
72_warn_if_electron_outdated() {
73 local _installed _latest_local _vf _v
74
75 [[ -r "/usr/lib/${_electron_pkg}/version" ]] || return 0
76 _installed=$(< "/usr/lib/${_electron_pkg}/version")
77 _latest_local=$_installed
78
79 shopt -s nullglob
80 for _vf in /usr/lib/electron*/version; do
81 _v=$(< "$_vf")
82 if [[ "$(printf '%s\n%s\n' "$_latest_local" "$_v" | sort -V | tail -n1)" != "$_latest_local" ]]; then
83 _latest_local=$_v
84 fi
85 done
86 shopt -u nullglob
87
88 if [[ $_installed != "$_latest_local" ]]; then
89 echo "==> WARNING: Packaging uses not the latest major version of electron installed. ${_electron_pkg} ${_installed} is used, but a newer local Electron version (${_latest_local}) is available on the system." >&2
90 fi
91}
92
93prepare() (
94 local _car_path
95 local _expected_webui_cid
96 local _ipfs_path
97 local _kubo_version
98 local _webui_path="${srcdir}/webui-${_webui_cid}"
99
100 cd -- "${_pkgsrc}" || return 1
101
102 _expected_webui_cid=$(
103 sed -nE \
104 '/"build:webui:download"/s/.*[[:space:]]-c[[:space:]]+([^[:space:]\"]+).*/\1/p' \
105 package.json
106 )
107 [[ -n "${_expected_webui_cid}" ]] || {
108 printf '%s\n' 'Unable to determine the WebUI CID expected by upstream' >&2
109 return 1
110 }
111 [[ "${_webui_cid}" == "${_expected_webui_cid}" ]] || {
112 printf 'WebUI CID mismatch: PKGBUILD has %s, upstream expects %s\n' \
113 "${_webui_cid}" "${_expected_webui_cid}" >&2
114 printf 'Update _webui_cid and its source checksum before building.\n' >&2
115 return 1
116 }
117
118 _ipfs_path=$(mktemp -d --tmpdir "${pkgname}-kubo.XXXXXXXX") || return 1
119 trap 'rm -rf -- "${_ipfs_path}"' EXIT
120
121 _car_path=$(readlink -f -- "${srcdir}/webui-${_webui_cid}.car")
122 [[ -f "${_car_path}" ]] || {
123 printf 'WebUI CAR is missing: %s\n' "${_car_path}" >&2
124 return 1
125 }
126
127 IPFS_PATH="${_ipfs_path}" ipfs init --profile=server >/dev/null
128 IPFS_PATH="${_ipfs_path}" ipfs dag import "${_car_path}" >/dev/null
129
130 rm -rf -- "${_webui_path}"
131 IPFS_PATH="${_ipfs_path}" ipfs get "/ipfs/${_webui_cid}" -o "${_webui_path}"
132 [[ -f "${_webui_path}/index.html" ]] || {
133 printf 'Materialized WebUI is missing index.html: %s\n' "${_webui_path}" >&2
134 return 1
135 }
136
137 _kubo_version=$(sed -nE 's/^[[:space:]]*"kubo":[[:space:]]*"([^"]+)".*/\1/p' package.json)
138 [[ -n "${_kubo_version}" ]] || {
139 printf '%s\n' 'Unable to determine the bundled Kubo version' >&2
140 return 1
141 }
142
143 npm pkg set "allowScripts[kubo@${_kubo_version}]=false" --json
144 npm ci --no-audit --no-fund \
145 2> >(sed '/glob@11\.1\.0: Old versions of glob are not supported/d' >&2)
146
147 [[ ! -e node_modules/kubo/kubo/ipfs ]] || {
148 printf '%s\n' 'Unexpected bundled Kubo binary found after npm install' >&2
149 return 1
150 }
151)
152
153build() {
154 local -a _builder_options
155
156 _warn_if_electron_outdated
157 _electron_env
158 cd -- "${_pkgsrc}" || return 1
159
160 IPFS_WEBUI_PATH="${srcdir}/webui-${_webui_cid}" \
161 npm_config_offline=true npm run build
162
163 _builder_options=(
164 "-c.electronDist=/usr/lib/${_electron_pkg}"
165 "-c.electronVersion=${SYSTEM_ELECTRON_VERSION}"
166 )
167 npm_config_offline=true npm exec -- electron-builder --linux --dir --publish never \
168 "${_builder_options[@]}"
169}
170
171package() {
172 local _license
173 local _packaged_app="${srcdir}/${pkgname}-packaged-app"
174
175 mkdir -p -- "${pkgdir}/usr/lib/${pkgname}"
176 cp -a -- "${_pkgsrc}/dist/linux-unpacked/resources/." "${pkgdir}/usr/lib/${pkgname}/"
177 rm -rf -- "${_packaged_app}"
178 asar extract "${_pkgsrc}/dist/linux-unpacked/resources/app.asar" "${_packaged_app}"
179 [[ -d "${_packaged_app}/node_modules" ]] || {
180 printf '%s\n' 'Packaged application is missing node_modules' >&2
181 return 1
182 }
183 [[ -d "${_packaged_app}/assets/webui/static/js" ]] || {
184 printf '%s\n' 'Packaged application is missing WebUI JavaScript assets' >&2
185 return 1
186 }
187
188 install -Dm644 -- "${_pkgsrc}/assets/webui/ipfs-logo-512-ice.png" \
189 "${pkgdir}/usr/share/pixmaps/${pkgname}.png"
190 install -Dm644 -- "${_pkgsrc}/LICENSE" \
191 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
192 for _license in 'Inter-LICENSE.txt' 'Montserrat-OFL.txt'; do
193 install -Dm644 -- "${srcdir}/${_license}" \
194 "${pkgdir}/usr/share/licenses/${pkgname}/webui/${_license}"
195 done
196
197 while IFS= read -r -d '' _license; do
198 install -Dm644 -- "${_license}" \
199 "${pkgdir}/usr/share/licenses/${pkgname}/${_license#"${_packaged_app}/"}"
200 done < <(find "${_packaged_app}/node_modules" -type f \
201 \( -iname 'license*' -o -iname 'copying*' -o -iname 'notice*' \) -print0)
202 while IFS= read -r -d '' _license; do
203 install -Dm644 -- "${_license}" \
204 "${pkgdir}/usr/share/licenses/${pkgname}/webui/${_license##*/}"
205 done < <(find "${_packaged_app}/assets/webui/static/js" -maxdepth 1 -type f \
206 -name '*.LICENSE.txt' -print0)
207
208 sed "s|@ELECTRON_PKG@|${_electron_pkg}|" \
209 "${srcdir}/${pkgname}-startup.sh" \
210 | install -Dm755 /dev/stdin "${pkgdir}/usr/bin/${pkgname}"
211 install -Dm644 -- "${srcdir}/${pkgname}.desktop" \
212 "${pkgdir}/usr/share/applications/${pkgname}.desktop"
213
214 chmod -R u+rwX,go+rX,go-w -- "${pkgdir}"
215}
216

Changes since previous scan

--- PKGBUILD @ 2026-09-28 00:28
+++ PKGBUILD @ 2026-10-02 00:00
@@ -6,7 +6,7 @@
pkgname='ipfs-desktop'
pkgver='0.50.1'
-pkgrel=2
+pkgrel=3
epoch=1
pkgdesc='Desktop client for the InterPlanetary File System'
arch=('x86_64')
@@ -26,6 +26,7 @@
depends=(
"${_electron_pkg}"
'kubo>=0.43.1'
+ 'libappindicator'
)
makedepends=(
'asar'

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 17:21:20 Medium 1
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 21:44:41 Medium 1
2026-09-24 00:24:14 Low 2
2026-09-23 07:39:45 Medium 1
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion