lunar-client-bin

maintainer Felitendo · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads a prebuilt AppImage from the project's official CDN, which is a normal distribution method for this software; the source host, while not a standard domain, is plausibly owned by the project, and the AppImage is executed only during prepare() to extract its contents, not run arbitrary code.

Triggered rules

LOW Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt AppImage from the project's official CDN, which is a normal distribution method for this software; the source host, while not a standard domain, is plausibly owned by the project, and the AppImage is executed only during prepare() to extract its contents, not run arbitrary code.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:19 source=("${_pkgname}-${pkgver}.AppImage::https://launcherupdates.lunarclientcdn.com/${_appimage}")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Felitendo
2# This PKGBUILD is updated automatically:
3# https://github.com/Felitendo/PKGBUILDS
4
5pkgname=lunar-client-bin
6_pkgname=lunarclient
7pkgver=3.7.13
8pkgrel=1
9pkgdesc="PvP modpack for all modern versions of Minecraft (upstream AppImage)"
10arch=('x86_64')
11url="https://lunarclient.com"
12license=('LicenseRef-proprietary')
13depends=('fuse2' 'xorg-xrandr')
14provides=('lunar-client' 'lunarclient')
15conflicts=('lunar-client' 'lunarclient')
16options=('!strip' '!debug')
17# maintained by CI together with pkgver (upstream varies the filename suffix)
18_appimage="Lunar%20Client-3.7.13-ow.AppImage"
19source=("${_pkgname}-${pkgver}.AppImage::https://launcherupdates.lunarclientcdn.com/${_appimage}")
20sha256sums=('bd818ee8b7893c79a6a6e642061148beb395af9c0c8614b93c908c784bab69af')
21
22prepare() {
23 chmod +x "${_pkgname}-${pkgver}.AppImage"
24 "./${_pkgname}-${pkgver}.AppImage" --appimage-extract
25}
26
27build() {
28 # make the .desktop file work outside of the AppImage container
29 sed -i -E "s|Exec=AppRun|Exec=env DESKTOPINTEGRATION=false /usr/bin/${_pkgname}|" \
30 "squashfs-root/${_pkgname}.desktop"
31 # AppImage directory permissions are 700
32 chmod -R a-x+rX squashfs-root/usr
33}
34
35package() {
36 install -Dm755 "${srcdir}/${_pkgname}-${pkgver}.AppImage" \
37 "${pkgdir}/opt/${_pkgname}/${_pkgname}.AppImage"
38
39 install -Dm644 "${srcdir}/squashfs-root/${_pkgname}.desktop" \
40 "${pkgdir}/usr/share/applications/${_pkgname}.desktop"
41
42 install -Dm644 \
43 "${srcdir}/squashfs-root/usr/share/icons/hicolor/1024x1024/apps/${_pkgname}.png" \
44 "${pkgdir}/usr/share/icons/hicolor/512x512/apps/${_pkgname}.png"
45
46 install -dm755 "${pkgdir}/usr/bin"
47 ln -s "/opt/${_pkgname}/${_pkgname}.AppImage" "${pkgdir}/usr/bin/${_pkgname}"
48}
49

Changes since previous scan

--- PKGBUILD @ 2026-08-01 00:11
+++ PKGBUILD @ 2026-08-03 00:08
@@ -4,7 +4,7 @@
pkgname=lunar-client-bin
_pkgname=lunarclient
-pkgver=3.7.12
+pkgver=3.7.13
pkgrel=1
pkgdesc="PvP modpack for all modern versions of Minecraft (upstream AppImage)"
arch=('x86_64')
@@ -15,9 +15,9 @@
conflicts=('lunar-client' 'lunarclient')
options=('!strip' '!debug')
# maintained by CI together with pkgver (upstream varies the filename suffix)
-_appimage="Lunar%20Client-3.7.12-ow.AppImage"
+_appimage="Lunar%20Client-3.7.13-ow.AppImage"
source=("${_pkgname}-${pkgver}.AppImage::https://launcherupdates.lunarclientcdn.com/${_appimage}")
-sha256sums=('7364e876a59291d8b0b7d6c0efdacb988617e35e054e9c21a5814d071710bf98')
+sha256sums=('bd818ee8b7893c79a6a6e642061148beb395af9c0c8614b93c908c784bab69af')
prepare() {
chmod +x "${_pkgname}-${pkgver}.AppImage"

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 3
2026-08-02 00:16:08 LOW 3
2026-08-01 01:19:40 MEDIUM 2
2026-08-01 00:11:18 LOW 3
2026-07-31 00:14:10 LOW 3
2026-07-30 00:17:23 LOW 3
2026-07-29 00:25:53 LOW 3
2026-07-28 00:07:28 LOW 3
2026-07-27 00:24:32 LOW 3
2026-07-26 00:07:32 LOW 3
2026-07-25 00:13:44 LOW 3
2026-07-24 11:30:24 LOW 3
2026-07-24 11:27:50 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion