mendeley-reference-manager-electron

MEDIUM
maintainer Supernovatux 0 votes scanned 2026-10-05 23:40:58.404909
View on AUR
Why flagged

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source=("https://static.mendeley.com/bin/desktop/${_file}")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Supernovatux <thulashitharan.d at gmail dot com>
2_electron=electron40
3_pkgname='mendeley-reference-manager'
4pkgname=${_pkgname}-electron
5pkgver=2.149.0
6pkgrel=1
7pkgdesc="Mendeley Reference Manager using system provided electron for increased security and performance"
8arch=('x86_64')
9provides=("${_pkgname}")
10conflicts=("${_pkgname}")
11depends=("${_electron}" 'harfbuzz' 'libgl' 'libxss')
12url='https://www.mendeley.com/download-reference-manager'
13license=('custom')
14
15_file=${_pkgname}-${pkgver}-${CARCH}.AppImage
16source=("https://static.mendeley.com/bin/desktop/${_file}")
17sha256sums=('5daae2aca295ee1c96f88e647d12d65fbf324b60622c938bd7afd5c34bc6b308')
18
19options=('!strip')
20
21prepare() {
22 # Some parts taken from the orginal mendeley-reference-manager package
23 # Extract AppImage contents so we install bypassing every and all AppImage
24 # desktop integration/deployment mechanisms
25 chmod +x "${_file}"
26 "./${_file}" --appimage-extract &>/dev/null
27}
28
29package() {
30 install -d "$pkgdir"/usr/bin/
31 install -d "$pkgdir"/usr/lib/${_pkgname}/
32 install -d "$pkgdir"/usr/share/applications/
33 install -d "$pkgdir"/usr/share/icons/
34 echo '#!/bin/sh' >> "$pkgdir"/usr/bin/${_pkgname}
35 echo "exec ${_electron} /usr/lib/${_pkgname}/app.asar \"\$@\"" >> "$pkgdir"/usr/bin/${_pkgname}
36 chmod +x "${pkgdir}/usr/bin/${_pkgname}"
37
38 install -m644 squashfs-root/mendeley-reference-manager.png "$pkgdir"/usr/share/icons/
39
40 sed -i "s%Exec=AppRun%Exec=/usr/bin/${_pkgname}%g" squashfs-root/mendeley-reference-manager.desktop
41 install -m644 squashfs-root/mendeley-reference-manager.desktop "$pkgdir"/usr/share/applications/
42 install -m644 squashfs-root/resources/app.asar "$pkgdir"/usr/lib/${_pkgname}/
43 cp -r squashfs-root/resources/app.asar.unpacked "$pkgdir"/usr/lib/${_pkgname}/
44 find "$pkgdir"/usr/lib/${_pkgname}/app.asar.unpacked -type d -exec chmod 755 {} +
45}
46
47

Changes since previous scan

--- PKGBUILD @ 2026-06-20 16:03
+++ PKGBUILD @ 2026-10-05 23:40
@@ -1,10 +1,10 @@
# Maintainer: Supernovatux <thulashitharan.d at gmail dot com>
-_electron=electron
+_electron=electron40
_pkgname='mendeley-reference-manager'
pkgname=${_pkgname}-electron
-pkgver=2.143.0
+pkgver=2.149.0
pkgrel=1
-pkgdesc="Mendeley Reference Manager using system provided ${_electron} for increased security and performance"
+pkgdesc="Mendeley Reference Manager using system provided electron for increased security and performance"
arch=('x86_64')
provides=("${_pkgname}")
conflicts=("${_pkgname}")
@@ -14,7 +14,7 @@
_file=${_pkgname}-${pkgver}-${CARCH}.AppImage
source=("https://static.mendeley.com/bin/desktop/${_file}")
-sha256sums=('c563d8638a9f46362eb130b4f720db8bf310f7d46334788f7fdb8b72a59eb81f')
+sha256sums=('5daae2aca295ee1c96f88e647d12d65fbf324b60622c938bd7afd5c34bc6b308')
options=('!strip')
@@ -40,6 +40,8 @@
sed -i "s%Exec=AppRun%Exec=/usr/bin/${_pkgname}%g" squashfs-root/mendeley-reference-manager.desktop
install -m644 squashfs-root/mendeley-reference-manager.desktop "$pkgdir"/usr/share/applications/
install -m644 squashfs-root/resources/app.asar "$pkgdir"/usr/lib/${_pkgname}/
+ cp -r squashfs-root/resources/app.asar.unpacked "$pkgdir"/usr/lib/${_pkgname}/
+ find "$pkgdir"/usr/lib/${_pkgname}/app.asar.unpacked -type d -exec chmod 755 {} +
}

Scan history

Scanned at (UTC)SeverityRules
2026-10-05 23:40:58 Medium 1
2026-06-20 16:03:41 Clean 2
2026-06-20 00:50:07 Medium 2
2026-06-20 00:18:46 Medium 1
2026-06-19 23:51:18 Medium 2
2026-06-19 19:07:35 Low 2
2026-06-18 16:11:54 Medium 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion