nirilayout-bin

MEDIUM
maintainer Piero-93 0 votes scanned 2026-10-07 20:06:42.279410
View on AUR
Why flagged

The package installs a prebuilt binary from a non-whitelisted, personal GitHub release URL without a clear upstream source for verification, creating a supply-chain risk if the binary were swapped.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 90%): The package installs a prebuilt binary from a non-whitelisted, personal GitHub release URL without a clear upstream source for verification, creating a supply-chain risk if the binary were swapped.

PKGBUILD

1# Maintainer: Piero <biagini93@ik.me>
2pkgname=nirilayout-bin
3_pkgname=nirilayout
4pkgver=0.4.0
5pkgrel=1
6pkgdesc="Quickly switch niri output configuration between different layouts (GTK switcher, prebuilt binary)"
7arch=('x86_64')
8url="https://github.com/Piero-93/nirilayout"
9license=('MIT')
10depends=('gtk4' 'gtk4-layer-shell' 'glib2' 'cairo' 'pango' 'gdk-pixbuf2' 'graphene' 'glibc')
11provides=("$_pkgname")
12conflicts=("$_pkgname")
13options=('!strip' '!debug')
14source=("$_pkgname-$pkgver::$url/releases/download/v$pkgver/$_pkgname"
15 "LICENSE-$pkgver::https://raw.githubusercontent.com/Piero-93/nirilayout/v$pkgver/LICENSE"
16 "README-$pkgver.md::https://raw.githubusercontent.com/Piero-93/nirilayout/v$pkgver/README.md")
17sha256sums=('6ce70c026bc8284b32effcb7fe66bff6245f4379b50aecb4254c09001d3e4d01'
18 '25f0a4e4c698ba4069be66bfda51c61ae2067ee7882d542b2f254ea3e7dce39e'
19 'bce69396952f4cd274f065b4e69bd7bcb69520f299944da96c4fd73b402c941d')
20
21package() {
22 install -Dm755 "$_pkgname-$pkgver" "$pkgdir/usr/bin/$_pkgname"
23 install -Dm644 "LICENSE-$pkgver" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
24 install -Dm644 "README-$pkgver.md" "$pkgdir/usr/share/doc/$pkgname/README.md"
25}
26

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 20:06:42 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion