minimax-code

LOW
maintainer duanluan 0 votes scanned 2026-10-06 12:02:18.455551
View on AUR
Why flagged

The package installs a Node.js application from npm and compiles native dependencies locally; while it downloads code from a non-whitelisted source (npm), it uses the system Node.js and builds dependencies from source, reducing supply-chain risk, and the installed code is not obfuscated or maliciously redirected.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a Node.js application from npm and compiles native dependencies locally; while it downloads code from a non-whitelisted source (npm), it uses the system Node.js and builds dependencies from source, reducing supply-chain risk, and the installed code is not obfuscated or maliciously redirected.

PKGBUILD

1# Maintainer: duanluan <duanluan@outlook.com>
2
3pkgname=minimax-code
4_pkgname='@minimax-ai/code'
5pkgver=0.6.3
6pkgrel=1
7# upstream optionalDependencies pin
8_better_sqlite3_ver=12.11.1
9pkgdesc='MiniMax Code terminal AI coding agent (mcode CLI)'
10arch=('x86_64' 'aarch64')
11url='https://agent.minimax.cn/download'
12license=('MIT')
13depends=(
14 'gcc-libs'
15 'glibc'
16 'nodejs>=22.19'
17)
18makedepends=(
19 'node-gyp'
20 'npm'
21 'python'
22)
23optdepends=(
24 'git: version control features'
25)
26options=('!strip')
27source=('LICENSE')
28sha256sums=('9d8b53a4e5afaa1b1cae3e7e5048952cd09050722951cab6638163500e0b3579')
29
30prepare() {
31 cd "${srcdir}"
32
33 rm -rf app
34 install -dm755 app
35 cd app
36
37 # 固定用系统 /usr/bin/node 附带的 npm 安装,保证后面编译的原生绑定和运行时 ABI(Node 内部模块版本)一致
38 PATH="/usr/bin:/usr/sbin:/bin" /usr/bin/npm install \
39 --ignore-scripts \
40 --no-audit \
41 --no-fund \
42 --omit=dev \
43 "${_pkgname}@${pkgver}" \
44 "better-sqlite3@${_better_sqlite3_ver}"
45
46 # 上游 better-sqlite3 的 install 脚本会下载预编译绑定,打包时改为用系统 Node 头文件本地编译
47 cd "${srcdir}/app/node_modules/better-sqlite3"
48 /usr/bin/node-gyp rebuild --release --nodedir=/usr
49
50 cd "${srcdir}/app/node_modules"
51
52 # ripgrep 和剪贴板库带了各平台预编译包,只保留当前架构用到的
53 local keep_rid keep_cid entry
54 case "${CARCH}" in
55 x86_64)
56 keep_rid='ripgrep-linux-x64'
57 keep_cid='clipboard-linux-x64-gnu'
58 ;;
59 aarch64)
60 keep_rid='ripgrep-linux-arm64'
61 keep_cid='clipboard-linux-arm64-gnu'
62 ;;
63 *)
64 printf 'unsupported architecture: %s\n' "${CARCH}" >&2
65 return 1
66 ;;
67 esac
68
69 for entry in @vscode/ripgrep-* @mariozechner/clipboard-*; do
70 case "${entry}" in
71 "@vscode/${keep_rid}"|"@mariozechner/${keep_cid}") ;;
72 *) rm -rf "${entry}" ;;
73 esac
74 done
75
76 # macOS / Windows 的原生小模块和 Windows 启动脚本在 Linux 上不会被加载
77 rm -rf "${srcdir}/app/node_modules/${_pkgname}/native/darwin" \
78 "${srcdir}/app/node_modules/${_pkgname}/native/win32"
79 rm -f "${srcdir}/app/node_modules/${_pkgname}/internal-bin/mcode-tools.cmd"
80 chmod 755 "${srcdir}/app/node_modules/${_pkgname}/internal-bin/mcode-tools"
81
82 # 清掉 better-sqlite3 的编译中间产物,只留编译好的绑定
83 cd "${srcdir}/app/node_modules/better-sqlite3"
84 rm -rf deps src build/Release/obj.target build/Release/.deps docs test benchmark
85 rm -f binding.gyp Makefile build/Makefile build/*.mk build/config.gypi
86}
87
88package() {
89 cd "${srcdir}"
90
91 install -dm755 "${pkgdir}/opt/${pkgname}"
92 cp -a app/node_modules "${pkgdir}/opt/${pkgname}/node_modules"
93
94 find "${pkgdir}/opt/${pkgname}" -type d -exec chmod 755 '{}' +
95 find "${pkgdir}/opt/${pkgname}" -type f -perm /111 -exec chmod 755 '{}' +
96 find "${pkgdir}/opt/${pkgname}" -type f ! -perm /111 -exec chmod 644 '{}' +
97
98 # 启动器固定走系统 Node:原生绑定是按它编译的,换别的 Node 可能加载失败
99 install -Dm755 /dev/stdin "${pkgdir}/usr/bin/mcode" <<'SCRIPT'
100#!/bin/sh
101exec /usr/bin/node /opt/minimax-code/node_modules/@minimax-ai/code/cli.js "$@"
102SCRIPT
103 install -Dm755 /dev/stdin "${pkgdir}/usr/bin/mcode-tools" <<'SCRIPT'
104#!/bin/sh
105exec /usr/bin/node /opt/minimax-code/node_modules/@minimax-ai/code/mcode-tools.js "$@"
106SCRIPT
107
108 install -Dm644 "${srcdir}/LICENSE" \
109 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
110}
111

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 12:02:18 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion