jasp-desktop-bin

MEDIUM
maintainer asger.weirsoe 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

A prebuilt binary tarball is downloaded from a personal server (asger.weirsoe.dk) unrelated to the official JASP upstream infrastructure; while a sha256 checksum is provided, the binary is not an official upstream artifact and could be silently swapped on a personal host, making this an unverifiable prebuilt executable from a swappable non-project-owned source.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:57 source=("https://asger.weirsoe.dk/tarballz/jasp-desktop-0.98.1-b36ed75bbd4f-x86_64.tar.zst")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 85%): A prebuilt binary tarball is downloaded from a personal server (asger.weirsoe.dk) unrelated to the official JASP upstream infrastructure; while a sha256 checksum is provided, the binary is not an official upstream artifact and could be silently swapped on a personal host, making this an unverifiable prebuilt executable from a swappable non-project-owned source.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Asger Geel Weirsoe <asger at weircon dot dk>
2#
3# PROVENANCE OF THE BINARY
4#
5# Upstream JASP publishes installers for Windows and macOS only; the official
6# Linux channel is Flathub. The binary this package installs is therefore NOT an
7# upstream release artifact. It is compiled from the tagged JASP sources
8# (v0.98.1, commit 077322e8269c1ace3bd14b6dfe7059f606fc0bc6) against an Arch Linux userland, in an
9# archlinux:base-devel container, by an automated pipeline:
10#
11# build recipe: https://gitea.weircon.dk/agw/jasp-desktop-bin
12# download: https://asger.weirsoe.dk/tarballz/jasp-desktop-0.98.1-b36ed75bbd4f-x86_64.tar.zst
13#
14# It bundles its own R 4.5.3 and the non-system libraries it links against
15# under /opt/jasp-desktop, so it does not constrain the versions of anything on
16# your system. Built against Qt 6.11.
17
18pkgname=jasp-desktop-bin
19pkgver=0.98.1
20pkgrel=1
21pkgdesc="JASP Desktop - a fresh way to do statistics (prebuilt binary)"
22arch=('x86_64')
23url="https://jasp-stats.org/"
24license=('AGPL-3.0-or-later')
25
26provides=("jasp-desktop=${pkgver}")
27conflicts=('jasp-desktop')
28
29# This package ships its own R 4.5.3 plus the non-system libraries it and
30# the JASP R modules link against (ICU, jsoncpp, glpk, JAGS, readstat, librdata,
31# BLAS/LAPACK ...) under /opt/jasp-desktop/lib, with rpath pointing there.
32#
33# That is deliberate, and it is why nothing below is version-pinned: on a rolling
34# distro a pin like 'icu<79' would make pacman refuse to upgrade ICU while JASP
35# is installed, blocking the user's entire system upgrade. Bundling means JASP
36# never constrains the system.
37#
38# Qt6 is the exception and stays a system dependency: Qt guarantees binary
39# compatibility across Qt 6 minor releases, and bundling QtWebEngine would add
40# ~500 MB for no real gain. A Qt 7 transition will need a rebuild.
41depends=(
42 'qt6-base' 'qt6-declarative' 'qt6-svg' 'qt6-positioning' 'qt6-webchannel'
43 'qt6-webengine' 'qt6-5compat' 'qt6-httpserver'
44 'fontconfig' 'freetype2' 'libxkbcommon' 'hicolor-icon-theme'
45)
46
47# The tarball is a complete, already-verified /opt + /usr install tree, so every
48# one of makepkg's tidying steps is unwanted here: they would modify content
49# that was tested in exactly this form. Stripping in particular would be slow
50# and is a good way to break a bundled R plus several hundred compiled R
51# modules, and the rpath set at build time must survive untouched.
52options=('!strip' '!debug' '!libtool' '!staticlibs' '!zipman' '!purge' '!emptydirs')
53
54# The remote name is content-addressed, so it is kept as the local name too: a
55# stale download left in the build directory can never be mistaken for the
56# current tarball and fail the checksum.
57source=("https://asger.weirsoe.dk/tarballz/jasp-desktop-0.98.1-b36ed75bbd4f-x86_64.tar.zst")
58sha256sums=('b36ed75bbd4ff5b91156362ac861fcf49df9cb30b0134009f4c8d2e187777dc8')
59
60package() {
61 cp -a "${srcdir}/opt" "${pkgdir}/opt"
62 cp -a "${srcdir}/usr" "${pkgdir}/usr"
63
64 # The application lives under /opt; give it a name on PATH.
65 install -d "${pkgdir}/usr/bin"
66 ln -s /opt/jasp-desktop/bin/JASP "${pkgdir}/usr/bin/jasp"
67}
68

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Medium 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion