materialious
The flagged npx calls are legitimate: 'npx cap telemetry off' disables Capacitor telemetry, 'npx cap sync @capacitor-community/electron' syncs the Capacitor Electron platform (both use the locally installed 'cap' CLI from npm ci), and 'npx electron-builder build' invokes the locally installed electron-builder. None of these fetch remote packages at runtime since npm ci has already installed all dependencies from the lockfile into node_modules. The PKGBUILD sources are from the official GitHub release tarball with pinned sha256sums. The nvm usage is a common (if non-ideal) AUR pattern for managing Node.js versions. The main concern is that npm ci downloads packages from the npm registry during build without checksums verified by makepkg, which is a standard low-severity supply-chain concern for Node.js AUR packages, not active malware.
Triggered rules
llm_review
The static rules flagged this HIGH, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): The flagged npx calls are legitimate: 'npx cap telemetry off' disables Capacitor telemetry, 'npx cap sync @capacitor-community/electron' syncs the Capacitor Electron platform (both use the locally installed 'cap' CLI from npm ci), and 'npx electron-builder build' invokes the locally installed electron-builder. None of these fetch remote packages at runtime since npm ci has already installed all dependencies from the lockfile into node_modules. The PKGBUILD sources are from the official GitHub release tarball with pinned sha256sums. The nvm usage is a common (if non-ideal) AUR pattern for managing Node.js versions. The main concern is that npm ci downloads packages from the npm registry during build without checksums verified by makepkg, which is a standard low-severity supply-chain concern for Node.js AUR packages, not active malware.
1 higher static finding superseded - not the current verdict (shown for transparency)
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell.
-
PKGBUILD:58
npx cap telemetry off -
PKGBUILD:59
npx cap sync @capacitor-community/electron -
PKGBUILD:65
npx electron-builder build --linux dir -c ./electron-builder.config.json \
PKGBUILD
3 offending line(s) highlighted# Maintainer: Mark Wagie <mark dot wagie at proton dot me>
pkgname=materialious
_app_id=us.materialio.Materialious
pkgver=1.18.6
pkgrel=1
_nodeversion=24
_electronversion=44
pkgdesc="Modern material design for Invidious."
arch=('x86_64')
url="https://materialio.us"
license=('AGPL-3.0-or-later')
depends=("electron${_electronversion}")
makedepends=(
'desktop-file-utils'
'nvm'
'python'
)
checkdepends=('appstream')
source=("Materialious-$pkgver.tar.gz::https://github.com/Materialious/Materialious/archive/refs/tags/$pkgver.tar.gz"
"$pkgname.sh")
sha256sums=('319205a7759b57fa74c18438b16235c31f58cdf1b250d1bec6693e224396605a'
'ae23af6865ab1638d46df5158fa09d41357f57068f1676af86e1a0e6e00459ed')
_ensure_local_nvm() {
# let's be sure we are starting clean
which nvm >/dev/null 2>&1 && nvm deactivate && nvm unload
export NVM_DIR="$srcdir/.nvm"
# The init script returns 3 if version specified
# in ./.nvrc is not (yet) installed in $NVM_DIR
# but nvm itself still gets loaded ok
source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
}
prepare() {
_ensure_local_nvm
nvm install "${_nodeversion}"
cd "Materialious-$pkgver/$pkgname"
# Set desktop file Exec
desktop-file-edit --set-key=Exec --set-value="$pkgname" "electron/$pkgname.desktop"
# Set Electron version
sed -i "s|@ELECTRONVERSION@|${_electronversion}|" "$srcdir/$pkgname.sh"
}
build() {
cd "Materialious-$pkgver/$pkgname"
export npm_config_cache="$srcdir/npm_cache"
export ELECTRON_SKIP_BINARY_DOWNLOAD=1
electronDist="/usr/lib/electron${_electronversion}"
electronVer="$(sed s/^v// /usr/lib/electron${_electronversion}/version)"
_ensure_local_nvm
npm ci
npm run build
npm prune --omit=dev
npx cap telemetry off
npx cap sync @capacitor-community/electron
cd electron
python patch_capacitor_plugin.py
npm ci
npm run build
npx electron-builder build --linux dir -c ./electron-builder.config.json \
-c.electronDist=$electronDist -c.electronVersion=$electronVer
}
check() {
cd "Materialious-$pkgver/$pkgname/electron"
appstreamcli validate --no-net "$pkgname.metainfo.xml" || :
desktop-file-validate "$pkgname.desktop"
}
package() {
cd "Materialious-$pkgver/$pkgname/electron"
install -Dm644 dist/linux-unpacked/resources/app.asar -t "$pkgdir/usr/lib/$pkgname/"
cp -a dist/linux-unpacked/resources/app.asar.unpacked -t "$pkgdir/usr/lib/$pkgname/"
install -Dm644 assets/appIcon.png \
"$pkgdir/usr/share/icons/hicolor/512x512/apps/${_app_id}.png"
install -Dm644 "$pkgname.desktop" "$pkgdir/usr/share/applications/${_app_id}.desktop"
install -Dm644 "$pkgname.metainfo.xml" "$pkgdir/usr/share/metainfo/${_app_id}.metainfo.xml"
install -Dm755 "$srcdir/$pkgname.sh" "$pkgdir/usr/bin/$pkgname"
}
Changes since previous scan
--- PKGBUILD @ 2026-09-17 00:27+++ PKGBUILD @ 2026-10-02 00:00@@ -1,7 +1,7 @@ # Maintainer: Mark Wagie <mark dot wagie at proton dot me> pkgname=materialious _app_id=us.materialio.Materialious-pkgver=1.18.5+pkgver=1.18.6 pkgrel=1 _nodeversion=24 _electronversion=44@@ -18,7 +18,7 @@ checkdepends=('appstream') source=("Materialious-$pkgver.tar.gz::https://github.com/Materialious/Materialious/archive/refs/tags/$pkgver.tar.gz" "$pkgname.sh")-sha256sums=('5db6086d6dc26b036f562a27a73f1c4dd32224d2e6d5c86df32ac71b42938ad9'+sha256sums=('319205a7759b57fa74c18438b16235c31f58cdf1b250d1bec6693e224396605a' 'ae23af6865ab1638d46df5158fa09d41357f57068f1676af86e1a0e6e00459ed') _ensure_local_nvm() {Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 17:27:25 | Low | 2 |
| 2026-09-17 17:25:53 | High | 1 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 17:23:26 | High | 1 |
| 2026-09-16 00:03:17 | Low | 2 |