moonlight-vrr-bin

LOW
maintainer Felitendo 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package installs a prebuilt AppImage from the project's official GitHub releases, which is unpacked and installed without modification; while the host is not whitelisted, it is the legitimate upstream source, and no remote code execution or obfuscation is present.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt AppImage from the project's official GitHub releases, which is unpacked and installed without modification; while the host is not whitelisted, it is the legitimate upstream source, and no remote code execution or obfuscation is present.

PKGBUILD

1# Maintainer: Felitendo
2# This PKGBUILD is updated automatically:
3# https://git.felo.gg/Felitendo/PKGBUILDS
4
5pkgname=moonlight-vrr-bin
6pkgver=6.1.0_vrr18
7pkgrel=1
8pkgdesc="GameStream client for PCs, fork of moonlight-qt with smooth VRR pacing (upstream AppImage)"
9arch=('x86_64')
10url="https://github.com/Nonary/moonlight-qt"
11license=('GPL-3.0-or-later')
12# the AppImage bundles Qt6, FFmpeg, SDL, libplacebo and the rest of the stack;
13# these are what is left over
14depends=('e2fsprogs' 'fontconfig' 'freetype2' 'glibc' 'harfbuzz'
15 'hicolor-icon-theme' 'libdrm' 'libgcc' 'libglvnd' 'libgpg-error' 'libice'
16 'libsm' 'libstdc++' 'libx11' 'libxcb' 'zlib')
17optdepends=('libva-intel-driver: hardware acceleration for Intel GPUs up to Coffee Lake'
18 'intel-media-driver: hardware acceleration for Intel GPUs from Broadwell on')
19provides=('moonlight-vrr' 'moonlight-qt')
20conflicts=('moonlight-vrr' 'moonlight-qt')
21options=('!strip' '!debug')
22# upstream tags use hyphens (v6.1.0-vrr18), which pkgver must not contain
23_upver="${pkgver//_/-}"
24source=("${pkgname}-${pkgver}.AppImage::${url}/releases/download/v${_upver}/Moonlight-${_upver}-x86_64.AppImage")
25noextract=("${pkgname}-${pkgver}.AppImage")
26sha256sums=('5b5992eb0d9d6528ca6db83c33da3bf6cbecea0f5a8f7b9b34dcd5d22d13f40c')
27
28prepare() {
29 chmod +x "$srcdir/${pkgname}-${pkgver}.AppImage"
30 "$srcdir/${pkgname}-${pkgver}.AppImage" --appimage-extract > /dev/null
31}
32
33package() {
34 local _root="$srcdir/squashfs-root"
35
36 # upstream's AppImage payload, installed unchanged
37 install -d "$pkgdir/opt/$pkgname"
38 cp -a "$_root/usr/." "$pkgdir/opt/$pkgname/"
39 # the squashfs has private directories and world writable files
40 chmod -R u=rwX,go=rX "$pkgdir/opt/$pkgname"
41
42 # the binary has a RUNPATH into the bundle and reads the qt.conf next to it,
43 # so it has to be exec'd where it is
44 install -d "$pkgdir/usr/bin"
45 cat > "$pkgdir/usr/bin/moonlight" << EOF
46#!/bin/sh
47exec /opt/$pkgname/bin/moonlight "\$@"
48EOF
49 chmod 755 "$pkgdir/usr/bin/moonlight"
50
51 install -Dm644 "$_root/com.moonlight_stream.Moonlight.desktop" \
52 "$pkgdir/usr/share/applications/com.moonlight_stream.Moonlight.desktop"
53 sed -i '/^X-AppImage-/d' "$pkgdir/usr/share/applications/com.moonlight_stream.Moonlight.desktop"
54 install -Dm644 "$_root/usr/share/metainfo/com.moonlight_stream.Moonlight.appdata.xml" \
55 "$pkgdir/usr/share/metainfo/com.moonlight_stream.Moonlight.appdata.xml"
56 install -Dm644 "$_root/usr/share/icons/hicolor/scalable/apps/moonlight.svg" \
57 "$pkgdir/usr/share/icons/hicolor/scalable/apps/moonlight.svg"
58}
59

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion