mercurygram-desktop-git
The package builds from source using publicly available Git repositories with SKIP'd checksums, which is common for -git packages; no remote code execution or malicious payloads are present, and the dependencies are standard for a Telegram fork.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from source using publicly available Git repositories with SKIP'd checksums, which is common for -git packages; no remote code execution or malicious payloads are present, and the dependencies are standard for a Telegram fork.
PKGBUILD
# Maintainer: Timothy Redaelli <timothy@fsfe.org>
# Based on telegram-desktop PKGBUILD
# Contributor: Sven-Hendrik Haase <svenstaro@archlinux.org>
# Contributor: hexchain <i@hexchain.org>
pkgname=mercurygram-desktop-git
pkgver=v7.2.10.1.beta.r0.gb2f6c20
pkgrel=1
pkgdesc='Privacy-focused Telegram Desktop fork'
arch=('x86_64')
url="https://mercurygram.org/"
license=('GPL-3.0-or-later WITH OpenSSL-exception')
depends=(
'abseil-cpp'
'ada'
'ffmpeg'
'glib2'
'glibc'
'hicolor-icon-theme'
'hunspell'
'kcoreaddons'
'libavif'
'libfido2'
'libgcc'
'libheif'
'libjpeg-turbo'
'libjxl'
'libpipewire'
'libsrtp'
'libstdc++'
'libvpx'
'libxcb'
'libxcomposite'
'libxdamage'
'libxext'
'libxfixes'
'libxkbcommon'
'libxrandr'
'libxtst'
'lz4'
'minizip'
'openal'
'openh264'
'openssl'
'opus'
'pipewire'
'qt6-base'
'qt6-declarative'
'qt6-imageformats'
'qt6-svg'
'qt6-wayland'
'rnnoise'
'tlottie'
'xxhash'
'zlib'
)
makedepends=(
'boost'
'boost-libs'
'cmake'
'git'
'glib2-devel'
'gobject-introspection'
'qt6-shadertools'
'gperf'
'libtg_owt'
'microsoft-gsl'
'ninja'
'python'
'range-v3'
'tl-expected'
'vulkan-headers'
)
optdepends=(
'geoclue: geoinformation support'
'crow-translate: translation provider'
'webkit2gtk-4.1: embedded browser features provided by webkit2gtk-4.1 (gtk3)'
'webkitgtk-6.0: embedded browser features provided by webkitgtk-6.0 (gtk4)'
'xdg-desktop-portal: desktop integration'
)
source=(
"${pkgname%-git}"::"git+https://github.com/Mercurygram/mdesktop.git"
"${pkgname%-git}_tdlib"::"git+https://github.com/tdlib/td.git"
)
sha512sums=('SKIP'
'SKIP')
pkgver() {
cd "$srcdir/${pkgname%-git}"
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g'
}
prepare() {
cd "$srcdir/${pkgname%-git}"
git submodule update --init --recursive --depth=1
}
build() {
cmake -S "$srcdir/${pkgname%-git}_tdlib" -B "${pkgname%-git}_tdlib/build" \
-DCMAKE_BUILD_TYPE=None \
-DCMAKE_INSTALL_PREFIX="$PWD/${pkgname%-git}_tdlib/install" \
-Wno-author \
-DTD_E2E_ONLY=ON
cmake --build "${pkgname%-git}_tdlib/build"
cmake --install "${pkgname%-git}_tdlib/build"
cmake -B build -S "$srcdir/${pkgname%-git}" -G Ninja \
-DCMAKE_VERBOSE_MAKEFILE=ON \
-DCMAKE_INSTALL_PREFIX="/usr" \
-Dtde2e_DIR="$PWD/${pkgname%-git}_tdlib/install/lib/cmake/tde2e" \
-DCMAKE_BUILD_TYPE=None \
-DTDESKTOP_API_ID=575730 \
-DTDESKTOP_API_HASH=723c7927097f8487d229438af766e329
cmake --build build
}
package() {
DESTDIR="$pkgdir" cmake --install build
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-28 21:21:47 | Low | 2 |