lando-beta
maintainer tiziodcaio
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The npx command is used to run @yao-pkg/pkg, a packaging tool, against the project's own source code during build; this is a legitimate build step for creating a standalone binary from a Node.js project and does not execute arbitrary remote code.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx command is used to run @yao-pkg/pkg, a packaging tool, against the project's own source code during build; this is a legitimate build step for creating a standalone binary from a Node.js project and does not execute arbitrary remote code.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
npx/bunx/deno executes a remote package
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:34
npx @yao-pkg/pkg --config package.json --target node22 --compress GZip --options dns-result-order=ipv4first bin/lando
PKGBUILD
1 offending line(s) highlighted
1
# Mantainer: Daniele Basso <d dot bass05 at pm dot me>
2
# Contributor: David Parrish <daveparrish@tutanota.com>
3
# Thank you inversechi and eschwartz
4
5
_pkgname=lando
6
pkgname=lando-beta
7
_pkgver=3.24.0
8
_beta=12
9
pkgver=${_pkgver}.b${_beta}
10
_target_version=${_pkgver}-beta.${_beta}
11
pkgrel=2
12
pkgdesc="A free, open source, cross-platform, local development environment and DevOps tool built on Docker container technology"
13
arch=('x86_64')
14
url="https://docs.lando.dev"
15
license=('GPL')
16
depends=('docker' 'docker-compose')
17
optdepends=('gcc-libs')
18
makedepends=('npm' 'git' 'nodejs')
19
source=("${_pkgname}-core::git+https://github.com/lando/core.git#tag=v${_target_version}")
20
sha256sums=('ea318069a0f1fb6224b08801322c92c88dbdb1e7560ed598eeaa1291e1a5bf47')
21
conflicts=("lando")
22
provides=("lando")
23
24
# strip breaks executable
25
options=(!strip)
26
27
build() {
28
cd "${srcdir}/$_pkgname-core" || exit
29
30
npm clean-install --prefer-offline --frozen-lockfile --omit=dev
31
# scripts/fatcore-install.sh
32
33
mkdir -p ./dist/@lando
34
npx @yao-pkg/pkg --config package.json --target node22 --compress GZip --options dns-result-order=ipv4first bin/lando
35
}
36
37
package() {
38
cd "${srcdir}/$_pkgname-core" || exit
39
install -D -m 755 "dist/@lando/core" "${pkgdir}/usr/bin/lando"
40
}
41
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |