mercurygram-desktop-git

LOW
maintainer tredaelli 0 votes scanned 2026-09-28 21:21:47.779666
View on AUR
Why flagged

The package builds from source using publicly available Git repositories with SKIP'd checksums, which is common for -git packages; no remote code execution or malicious payloads are present, and the dependencies are standard for a Telegram fork.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from source using publicly available Git repositories with SKIP'd checksums, which is common for -git packages; no remote code execution or malicious payloads are present, and the dependencies are standard for a Telegram fork.

PKGBUILD

1# Maintainer: Timothy Redaelli <timothy@fsfe.org>
2
3# Based on telegram-desktop PKGBUILD
4# Contributor: Sven-Hendrik Haase <svenstaro@archlinux.org>
5# Contributor: hexchain <i@hexchain.org>
6
7pkgname=mercurygram-desktop-git
8pkgver=v7.2.10.1.beta.r0.gb2f6c20
9pkgrel=1
10pkgdesc='Privacy-focused Telegram Desktop fork'
11arch=('x86_64')
12url="https://mercurygram.org/"
13license=('GPL-3.0-or-later WITH OpenSSL-exception')
14depends=(
15 'abseil-cpp'
16 'ada'
17 'ffmpeg'
18 'glib2'
19 'glibc'
20 'hicolor-icon-theme'
21 'hunspell'
22 'kcoreaddons'
23 'libavif'
24 'libfido2'
25 'libgcc'
26 'libheif'
27 'libjpeg-turbo'
28 'libjxl'
29 'libpipewire'
30 'libsrtp'
31 'libstdc++'
32 'libvpx'
33 'libxcb'
34 'libxcomposite'
35 'libxdamage'
36 'libxext'
37 'libxfixes'
38 'libxkbcommon'
39 'libxrandr'
40 'libxtst'
41 'lz4'
42 'minizip'
43 'openal'
44 'openh264'
45 'openssl'
46 'opus'
47 'pipewire'
48 'qt6-base'
49 'qt6-declarative'
50 'qt6-imageformats'
51 'qt6-svg'
52 'qt6-wayland'
53 'rnnoise'
54 'tlottie'
55 'xxhash'
56 'zlib'
57)
58makedepends=(
59 'boost'
60 'boost-libs'
61 'cmake'
62 'git'
63 'glib2-devel'
64 'gobject-introspection'
65 'qt6-shadertools'
66 'gperf'
67 'libtg_owt'
68 'microsoft-gsl'
69 'ninja'
70 'python'
71 'range-v3'
72 'tl-expected'
73 'vulkan-headers'
74)
75optdepends=(
76 'geoclue: geoinformation support'
77 'crow-translate: translation provider'
78 'webkit2gtk-4.1: embedded browser features provided by webkit2gtk-4.1 (gtk3)'
79 'webkitgtk-6.0: embedded browser features provided by webkitgtk-6.0 (gtk4)'
80 'xdg-desktop-portal: desktop integration'
81)
82source=(
83 "${pkgname%-git}"::"git+https://github.com/Mercurygram/mdesktop.git"
84 "${pkgname%-git}_tdlib"::"git+https://github.com/tdlib/td.git"
85)
86sha512sums=('SKIP'
87 'SKIP')
88
89pkgver() {
90 cd "$srcdir/${pkgname%-git}"
91 git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g'
92}
93
94prepare() {
95 cd "$srcdir/${pkgname%-git}"
96 git submodule update --init --recursive --depth=1
97}
98
99build() {
100 cmake -S "$srcdir/${pkgname%-git}_tdlib" -B "${pkgname%-git}_tdlib/build" \
101 -DCMAKE_BUILD_TYPE=None \
102 -DCMAKE_INSTALL_PREFIX="$PWD/${pkgname%-git}_tdlib/install" \
103 -Wno-author \
104 -DTD_E2E_ONLY=ON
105 cmake --build "${pkgname%-git}_tdlib/build"
106 cmake --install "${pkgname%-git}_tdlib/build"
107
108 cmake -B build -S "$srcdir/${pkgname%-git}" -G Ninja \
109 -DCMAKE_VERBOSE_MAKEFILE=ON \
110 -DCMAKE_INSTALL_PREFIX="/usr" \
111 -Dtde2e_DIR="$PWD/${pkgname%-git}_tdlib/install/lib/cmake/tde2e" \
112 -DCMAKE_BUILD_TYPE=None \
113 -DTDESKTOP_API_ID=575730 \
114 -DTDESKTOP_API_HASH=723c7927097f8487d229438af766e329
115 cmake --build build
116}
117
118package() {
119 DESTDIR="$pkgdir" cmake --install build
120}
121

Scan history

Scanned at (UTC)SeverityRules
2026-09-28 21:21:47 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion