materialious

LOW
maintainer yochananmarqos 1 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The flagged npx calls are legitimate: 'npx cap telemetry off' disables Capacitor telemetry, 'npx cap sync @capacitor-community/electron' syncs the Capacitor Electron platform (both use the locally installed 'cap' CLI from npm ci), and 'npx electron-builder build' invokes the locally installed electron-builder. None of these fetch remote packages at runtime since npm ci has already installed all dependencies from the lockfile into node_modules. The PKGBUILD sources are from the official GitHub release tarball with pinned sha256sums. The nvm usage is a common (if non-ideal) AUR pattern for managing Node.js versions. The main concern is that npm ci downloads packages from the npm registry during build without checksums verified by makepkg, which is a standard low-severity supply-chain concern for Node.js AUR packages, not active malware.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this HIGH, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): The flagged npx calls are legitimate: 'npx cap telemetry off' disables Capacitor telemetry, 'npx cap sync @capacitor-community/electron' syncs the Capacitor Electron platform (both use the locally installed 'cap' CLI from npm ci), and 'npx electron-builder build' invokes the locally installed electron-builder. None of these fetch remote packages at runtime since npm ci has already installed all dependencies from the lockfile into node_modules. The PKGBUILD sources are from the official GitHub release tarball with pinned sha256sums. The nvm usage is a common (if non-ideal) AUR pattern for managing Node.js versions. The main concern is that npm ci downloads packages from the npm registry during build without checksums verified by makepkg, which is a standard low-severity supply-chain concern for Node.js AUR packages, not active malware.

1 higher static finding superseded - not the current verdict (shown for transparency)
High npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell.

  • PKGBUILD:58 npx cap telemetry off
  • PKGBUILD:59 npx cap sync @capacitor-community/electron
  • PKGBUILD:65 npx electron-builder build --linux dir -c ./electron-builder.config.json \

PKGBUILD

3 offending line(s) highlighted
1# Maintainer: Mark Wagie <mark dot wagie at proton dot me>
2pkgname=materialious
3_app_id=us.materialio.Materialious
4pkgver=1.18.6
5pkgrel=1
6_nodeversion=24
7_electronversion=44
8pkgdesc="Modern material design for Invidious."
9arch=('x86_64')
10url="https://materialio.us"
11license=('AGPL-3.0-or-later')
12depends=("electron${_electronversion}")
13makedepends=(
14 'desktop-file-utils'
15 'nvm'
16 'python'
17)
18checkdepends=('appstream')
19source=("Materialious-$pkgver.tar.gz::https://github.com/Materialious/Materialious/archive/refs/tags/$pkgver.tar.gz"
20 "$pkgname.sh")
21sha256sums=('319205a7759b57fa74c18438b16235c31f58cdf1b250d1bec6693e224396605a'
22 'ae23af6865ab1638d46df5158fa09d41357f57068f1676af86e1a0e6e00459ed')
23
24_ensure_local_nvm() {
25 # let's be sure we are starting clean
26 which nvm >/dev/null 2>&1 && nvm deactivate && nvm unload
27 export NVM_DIR="$srcdir/.nvm"
28
29 # The init script returns 3 if version specified
30 # in ./.nvrc is not (yet) installed in $NVM_DIR
31 # but nvm itself still gets loaded ok
32 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
33}
34
35prepare() {
36 _ensure_local_nvm
37 nvm install "${_nodeversion}"
38
39 cd "Materialious-$pkgver/$pkgname"
40
41 # Set desktop file Exec
42 desktop-file-edit --set-key=Exec --set-value="$pkgname" "electron/$pkgname.desktop"
43
44 # Set Electron version
45 sed -i "s|@ELECTRONVERSION@|${_electronversion}|" "$srcdir/$pkgname.sh"
46}
47
48build() {
49 cd "Materialious-$pkgver/$pkgname"
50 export npm_config_cache="$srcdir/npm_cache"
51 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
52 electronDist="/usr/lib/electron${_electronversion}"
53 electronVer="$(sed s/^v// /usr/lib/electron${_electronversion}/version)"
54 _ensure_local_nvm
55 npm ci
56 npm run build
57 npm prune --omit=dev
58 npx cap telemetry off
59 npx cap sync @capacitor-community/electron
60
61 cd electron
62 python patch_capacitor_plugin.py
63 npm ci
64 npm run build
65 npx electron-builder build --linux dir -c ./electron-builder.config.json \
66 -c.electronDist=$electronDist -c.electronVersion=$electronVer
67}
68
69check() {
70 cd "Materialious-$pkgver/$pkgname/electron"
71 appstreamcli validate --no-net "$pkgname.metainfo.xml" || :
72 desktop-file-validate "$pkgname.desktop"
73}
74
75package() {
76 cd "Materialious-$pkgver/$pkgname/electron"
77 install -Dm644 dist/linux-unpacked/resources/app.asar -t "$pkgdir/usr/lib/$pkgname/"
78 cp -a dist/linux-unpacked/resources/app.asar.unpacked -t "$pkgdir/usr/lib/$pkgname/"
79 install -Dm644 assets/appIcon.png \
80 "$pkgdir/usr/share/icons/hicolor/512x512/apps/${_app_id}.png"
81 install -Dm644 "$pkgname.desktop" "$pkgdir/usr/share/applications/${_app_id}.desktop"
82 install -Dm644 "$pkgname.metainfo.xml" "$pkgdir/usr/share/metainfo/${_app_id}.metainfo.xml"
83 install -Dm755 "$srcdir/$pkgname.sh" "$pkgdir/usr/bin/$pkgname"
84}
85

Changes since previous scan

--- PKGBUILD @ 2026-09-17 00:27
+++ PKGBUILD @ 2026-10-02 00:00
@@ -1,7 +1,7 @@
# Maintainer: Mark Wagie <mark dot wagie at proton dot me>
pkgname=materialious
_app_id=us.materialio.Materialious
-pkgver=1.18.5
+pkgver=1.18.6
pkgrel=1
_nodeversion=24
_electronversion=44
@@ -18,7 +18,7 @@
checkdepends=('appstream')
source=("Materialious-$pkgver.tar.gz::https://github.com/Materialious/Materialious/archive/refs/tags/$pkgver.tar.gz"
"$pkgname.sh")
-sha256sums=('5db6086d6dc26b036f562a27a73f1c4dd32224d2e6d5c86df32ac71b42938ad9'
+sha256sums=('319205a7759b57fa74c18438b16235c31f58cdf1b250d1bec6693e224396605a'
'ae23af6865ab1638d46df5158fa09d41357f57068f1676af86e1a0e6e00459ed')
_ensure_local_nvm() {

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 17:27:25 Low 2
2026-09-17 17:25:53 High 1
2026-09-17 00:27:14 Low 2
2026-09-16 17:23:26 High 1
2026-09-16 00:03:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion