nodejs-redbird

maintainer orphaned · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package installs a Node.js module via npm from the official npm registry, which is a standard and expected practice for AUR Node.js packages; the flagged 'undeclared external package' is the same package being built, installed as part of its normal build process, not an unexpected or malicious dependency.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The package installs a Node.js module via npm from the official npm registry, which is a standard and expected practice for AUR Node.js packages; the flagged 'undeclared external package' is the same package being built, installed as part of its normal build process, not an unexpected or malicious dependency.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:21 npm install --user root -g --prefix "${pkgdir}/usr" "${pkgname#nodejs-}@${pkgver}"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Michal Wojdyla < micwoj9292 at gmail dot com >
2# Contributor: Fredy García <frealgagu at gmail dot com>
3
4pkgname=nodejs-redbird
5pkgver=0.10.0
6pkgrel=1
7pkgdesc="A modern reverse proxy for node"
8arch=("x86_64")
9url="https://github.com/OptimalBits/${pkgname#nodejs-}"
10license=("BSD")
11depends=("nodejs")
12makedepends=("npm" "python2")
13source=("https://registry.npmjs.org/${pkgname#nodejs-}/-/${pkgname#nodejs-}-${pkgver}.tgz")
14noextract=("${pkgname#nodejs-}-${pkgver}.tgz")
15sha1sums=("3027a6fcef7afebeaa8e5388bef283a84d308518")
16
17package() {
18 cd "${srcdir}"
19
20 echo "Installing using npm..."
21 npm install --user root -g --prefix "${pkgdir}/usr" "${pkgname#nodejs-}@${pkgver}"
22
23 echo "Installing license file in /usr/share/licenses/${pkgname} ..."
24 install -dm755 "${pkgdir}/usr/share/licenses/${pkgname}"
25 install -Dm755 "${pkgdir}/usr/lib/node_modules/${pkgname#nodejs-}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/"
26
27 echo "Changing permissions to remove the world writable bit set"
28 chmod go-w -R "${pkgdir}"
29}
30

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 3
2026-07-26 00:07:32 LOW 3
2026-07-25 00:13:44 LOW 3
2026-07-24 00:02:28 LOW 3
2026-07-23 00:14:47 LOW 3
2026-07-22 00:29:32 LOW 3
2026-07-21 00:24:15 LOW 3
2026-07-20 00:19:49 LOW 3
2026-07-19 00:17:08 LOW 3
2026-07-18 00:14:48 LOW 3
2026-07-17 00:06:16 LOW 3
2026-07-16 00:05:41 LOW 3
2026-07-15 00:09:25 LOW 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion