kitshell-git
maintainer tophar
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The PKGBUILD builds the project from its own Git source, uses rustup and cargo to install a build-time codegen tool (flutter_rust_bridge_codegen) required for the build, and does not execute untrusted prebuilt binaries or install runtime dependencies via cargo; this is a normal part of building a Flutter/Rust project, not a supply-chain risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The PKGBUILD builds the project from its own Git source, uses rustup and cargo to install a build-time codegen tool (flutter_rust_bridge_codegen) required for the build, and does not execute untrusted prebuilt binaries or install runtime dependencies via cargo; this is a normal part of building a Flutter/Rust project, not a supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
External install via pipx/uv/poetry/cargo/go/gem
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:31
cargo install flutter_rust_bridge_codegen
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Christopher Hartono <christhartono@hotmail.com>
2
## options
3
: ${_install_path:=usr/lib}
4
5
_pkgname="kitshell"
6
pkgname="kitshell-git"
7
pkgver=r229.c42f1ad
8
pkgrel=1
9
pkgdesc="An easy to use panel for Wayland WMs"
10
arch=(x86_64)
11
url="https://github.com/bootloopmaster636/kitshell"
12
license=('GPL-3.0-or-later')
13
options=('!debug')
14
15
depends=(glib2 libepoxy libxcb at-spi2-core pango cairo gtk-layer-shell dbus fontconfig gtk3 glibc gcc-libs)
16
makedepends=(git tar fvm rustup cmake ninja clang patchelf)
17
optdepends=('kitshell-cmd-git: control Kitshell via command line')
18
19
conflicts=('kitshell')
20
provides=('kitshell')
21
22
_pkgsrc="$_pkgname"
23
source=("$_pkgsrc"::"git+$url.git")
24
sha256sums=('SKIP')
25
26
prepare() {
27
cd "$_pkgsrc"
28
fvm use 3.38.2
29
rustup toolchain install stable
30
31
cargo install flutter_rust_bridge_codegen
32
}
33
34
pkgver() {
35
cd "$_pkgsrc"
36
( set -o pipefail
37
git describe --long --abbrev=7 2>/dev/null | sed 's/\([^-]*-g\)/r\1/;s/-/./g' ||
38
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
39
)
40
}
41
42
build() {
43
cd "$_pkgsrc"
44
PATH=$PATH:~/.cargo/bin/ # to make flutter_rust_codegen crate work
45
46
fvm flutter --disable-analytics
47
fvm dart --disable-analytics
48
49
fvm flutter pub get
50
fvm dart run slang build
51
fvm dart run build_runner build
52
flutter_rust_bridge_codegen generate
53
54
fvm flutter build linux --no-pub --release
55
}
56
57
package() {
58
cd "$_pkgsrc/build/linux/x64/release/bundle"
59
60
# Kitshell files
61
install -Dm755 "kitshell" "$pkgdir/$_install_path/$_pkgname/$_pkgname"
62
cp --reflink=auto -r data/ "$pkgdir/$_install_path/$_pkgname/"
63
cp --reflink=auto -r lib/ "$pkgdir/$_install_path/$_pkgname/"
64
65
# Runpath
66
patchelf --set-rpath '$ORIGIN/lib' "$pkgdir/$_install_path/$_pkgname/$_pkgname"
67
for i in "$pkgdir/$_install_path/$_pkgname/lib"/*.so; do
68
[ -z "$(patchelf --print-rpath "$i")" ] && continue
69
patchelf --set-rpath '$ORIGIN' "$i"
70
done
71
72
# Symlink
73
install -dm755 "${pkgdir}/usr/bin"
74
ln -sfr "$pkgdir/$_install_path/$_pkgname/$_pkgname" "$pkgdir/usr/bin/${_pkgname}"
75
76
# License
77
install -Dm644 "$srcdir/$_pkgsrc/LICENSE" -t "$pkgdir/usr/share/licenses/$pkgname/"
78
79
# Set permissions
80
chmod -R u+rwX,go+rX,go-w "$pkgdir/"
81
}
82
83
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |