ldtk-git

LOW
maintainer duanluan 0 votes scanned 2026-10-08 08:10:09.919119
View on AUR
Why flagged

The npx call runs electron-builder, which is already installed locally via npm install from the project's own package.json, not fetching an arbitrary remote package; the overall build follows normal AUR patterns for an Electron app from the project's own GitHub source, so there is no meaningful supply-chain risk beyond the usual npm dependency tree.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The npx call runs electron-builder, which is already installed locally via npm install from the project's own package.json, not fetching an arbitrary remote package; the overall build follows normal AUR patterns for an Electron app from the project's own GitHub source, so there is no meaningful supply-chain risk beyond the usual npm dependency tree.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:42 npx electron-builder build --linux --x64 --dir --publish never

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: duanluan <duanluan@outlook.com>
2# Contributor: Kacper Zybała <zyperpl at gmail dot com> (PKGBUILD 参考 AUR ldtk)
3
4pkgname=ldtk-git
5pkgver=1.5.3.r13.g2b7b551
6pkgrel=1
7pkgdesc='Modern and efficient 2D level editor with a strong focus on user-friendliness (git master)'
8arch=('x86_64')
9url='https://github.com/deepnight/ldtk'
10license=('MIT')
11depends=('gtk3' 'nss' 'alsa-lib' 'libxss' 'libxtst' 'libxcursor' 'libxi'
12 'libxcomposite' 'libxdamage' 'libxfixes' 'libxrandr' 'libxkbcommon'
13 'libdrm' 'mesa' 'at-spi2-core' 'cups' 'pango' 'libdbusmenu-glib')
14makedepends=('git' 'haxe' 'nodejs' 'npm')
15provides=('ldtk')
16conflicts=('ldtk')
17options=('!strip' '!makeflags')
18source=("git+${url}.git"
19 'ldtk-git.desktop')
20sha256sums=('SKIP'
21 '68ff7f1083f03bd93d773cff5edab3e8f7004dbdd0f0accbda69439affd2c008')
22
23pkgver() {
24 cd ldtk
25 git describe --long --tags --abbrev=7 | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
26}
27
28build() {
29 # 在 srcdir 建立本地 haxelib 仓库,避免污染全局 haxelib 安装
30 haxelib deleterepo --quiet --always
31 haxelib newrepo
32
33 cd ldtk
34 # 上游脚本:安装 haxelib 依赖(git 依赖跟随各库默认分支,与 master 构建一致)
35 haxe setup.hxml
36 haxelib list
37
38 cd app
39 npm install --cache "${srcdir}/npm-cache"
40 # pack-prepare 编译 Haxe 产物;--dir 只输出 linux-unpacked,跳过 AppImage/snap 安装器打包
41 npm run pack-prepare --cache "${srcdir}/npm-cache"
42 npx electron-builder build --linux --x64 --dir --publish never
43}
44
45package() {
46 cd ldtk
47 install -Dm644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
48
49 # electron-builder 产物:linux-unpacked 为解包目录,直接安装免去 AppImage 解包
50 cd app/redist/linux-unpacked
51 install -Dm644 LICENSE.electron.txt "${pkgdir}/usr/share/licenses/${pkgname}/"
52 install -Dm644 LICENSES.chromium.html "${pkgdir}/usr/share/licenses/${pkgname}/"
53 install -dm755 "${pkgdir}/usr/share/${pkgname}"
54 find . -type f -exec install -Dm755 '{}' "${pkgdir}/usr/share/${pkgname}/{}" \;
55
56 install -dm755 "${pkgdir}/usr/bin"
57 ln -s "/usr/share/${pkgname}/ldtk" "${pkgdir}/usr/bin/ldtk"
58
59 cd "${srcdir}/ldtk"
60 install -Dm644 app/assets/appIcon.png "${pkgdir}/usr/share/pixmaps/ldtk.png"
61 install -Dm644 "${srcdir}/ldtk-git.desktop" "${pkgdir}/usr/share/applications/${pkgname}.desktop"
62}
63

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 08:10:09 Low 3
2026-10-08 08:08:18 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion