mangodisk-bin

LOW
maintainer robertfoster 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package downloads prebuilt .deb files from the project's official GitHub releases, which is a normal source for binaries; the build process extracts and installs them without executing arbitrary remote code, and the software is open-source with verifiable checksums, making the risk low despite the binary distribution.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads prebuilt .deb files from the project's official GitHub releases, which is a normal source for binaries; the build process extracts and installs them without executing arbitrary remote code, and the software is open-source with verifiable checksums, making the risk low despite the binary distribution.

PKGBUILD

1# Maintainer: robertfoster
2pkgname=mangodisk-bin
3_pkgname="${pkgname%-bin}"
4_appname=MangoDisk
5pkgver=1.1.6 # renovate: datasource=github-releases depName=harry0703/MangoDisk
6pkgrel=1
7pkgdesc="Safety-first disk cleaner and space analyzer with duplicate cleanup and maintenance tools"
8arch=('x86_64' 'aarch64')
9url="https://github.com/harry0703/MangoDisk"
10license=('GPL-3.0-only')
11depends=('cairo' 'dbus' 'gdk-pixbuf2' 'glib2' 'glibc' 'gtk3' 'hicolor-icon-theme'
12 'libgcc' 'libsoup3' 'pango' 'webkit2gtk-4.1'
13 'libayatana-appindicator') # dlopen()ed for the resident tray icon
14optdepends=('xdg-utils: open folders and links from the app')
15provides=("${_pkgname}")
16conflicts=("${_pkgname}")
17options=('!debug')
18source=("LICENSE-${pkgver}::https://raw.githubusercontent.com/harry0703/MangoDisk/v${pkgver}/LICENSE")
19source_x86_64=("${url}/releases/download/v${pkgver}/${_appname}-${pkgver}-linux-x64.deb")
20source_aarch64=("${url}/releases/download/v${pkgver}/${_appname}-${pkgver}-linux-arm64.deb")
21noextract=("${_appname}-${pkgver}-linux-x64.deb" "${_appname}-${pkgver}-linux-arm64.deb")
22
23prepare() {
24 mkdir -p "${srcdir}/deb"
25 bsdtar -xOf "${srcdir}/${_appname}-${pkgver}"-linux-*.deb 'data.tar.*' |
26 bsdtar -xf - -C "${srcdir}/deb"
27
28 # upstream leaves Categories empty, so menus file the launcher under "Other"
29 sed -i 's/^Categories=.*/Categories=System;Utility;Filesystem;/' \
30 "${srcdir}/deb/usr/share/applications/${_appname}.desktop"
31}
32
33package() {
34 cd "${srcdir}/deb/usr"
35
36 install -Dm755 -t "${pkgdir}/usr/bin" "bin/${_appname}"
37 ln -s "${_appname}" "${pkgdir}/usr/bin/${_pkgname}"
38
39 install -Dm644 -t "${pkgdir}/usr/share/applications" \
40 "share/applications/${_appname}.desktop"
41
42 # tauri drops the 128x128@2x icon into a non-standard "256x256@2" directory
43 # that icon themes never look up; it is a plain 256x256 image
44 local _size
45 for _size in 32x32 128x128; do
46 install -Dm644 -t "${pkgdir}/usr/share/icons/hicolor/${_size}/apps" \
47 "share/icons/hicolor/${_size}/apps/${_appname}.png"
48 done
49 install -Dm644 -t "${pkgdir}/usr/share/icons/hicolor/256x256/apps" \
50 "share/icons/hicolor/256x256@2/apps/${_appname}.png"
51
52 install -Dm644 "${srcdir}/LICENSE-${pkgver}" \
53 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
54}
55
56sha256sums=('3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986')
57sha256sums_x86_64=('379cc6277000b73ac09322f2fd5409ce8be5c5b5a5a6f639b6d163299da6816c')
58sha256sums_aarch64=('327232e48743b58bbc4c1afa416a82dae0ade90c5a7ed7e59be9cbef60205fac')
59

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion