matcha-git

LOW
maintainer emersion 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The npm install runs on bundled source code from the project's own repository, not an external package, so it is part of the normal build process and not a supply-chain risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npm install runs on bundled source code from the project's own repository, not an external package, so it is part of the normal build process and not a supply-chain risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:24 (cd "$srcdir/src/$_gourl/public" && npm install)

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: emersion <contact emersion fr>
2
3_pkgname=matcha
4pkgname=matcha-git
5pkgver=0.1.0.r0.gb8269e1
6pkgrel=1
7pkgdesc="A read-only web interface for Git repositories"
8arch=('x86_64' 'i686')
9url="https://github.com/emersion/matcha"
10license=('MIT')
11makedepends=('go' 'npm')
12options=('!strip' '!emptydirs')
13source=('matcha::git+https://github.com/emersion/matcha')
14md5sums=('SKIP')
15_gourl=github.com/emersion/matcha
16
17pkgver() {
18 cd "$srcdir/matcha"
19 git describe --long --tags | sed 's/\([^-]*-g\)/r\1/;s/-/./g' | sed 's/^v//'
20}
21
22build() {
23 GOPATH="$srcdir" go get -ldflags "-X $_gourl.publicDir=/usr/share/webapps/$_pkgname" ${_gourl}/cmd/matcha
24 (cd "$srcdir/src/$_gourl/public" && npm install)
25}
26
27package() {
28 mkdir -p "$pkgdir/usr/bin"
29 install -p -m755 "$srcdir/bin/"* "$pkgdir/usr/bin"
30
31 mkdir -p "$pkgdir/usr/share/webapps/$_pkgname"
32 cp -R "$srcdir/src/$_gourl/public/"* "$pkgdir/usr/share/webapps/$_pkgname"
33
34 install -Dm644 "$srcdir/src/$_gourl/LICENSE" "$pkgdir/usr/share/licenses/$_pkgname/LICENSE"
35}
36

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion