omp-ctl

LOW
maintainer crowforkotlin 0 votes scanned 2026-10-06 08:09:03.243956
View on AUR
Why flagged

The package builds from its own GitHub source tarball with a pinned checksum; the 'bun install' fetches frontend dependencies from npm at build time (normal for Tauri/web projects), which is a mild supply-chain concern but not unusual for this type of package, and the rest of the build is a standard Rust/Tauri compilation with no obfuscated payloads or exfiltration.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The package builds from its own GitHub source tarball with a pinned checksum; the 'bun install' fetches frontend dependencies from npm at build time (normal for Tauri/web projects), which is a mild supply-chain concern but not unusual for this type of package, and the rest of the build is a standard Rust/Tauri compilation with no obfuscated payloads or exfiltration.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium bun install of an undeclared external package bun_install_external

`bun add` / `bun install <package>` fetches an external package outside source=(). Severity downgraded: the package declares/looks like a Node.js consumer.

  • PKGBUILD:25 (cd web && (bun install --frozen-lockfile || bun install) && bun run build)

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: moecly <moecly@users.noreply.github.com>
2pkgname=omp-ctl
3pkgver=0.6.0
4pkgrel=2
5pkgdesc='Desktop GUI for managing omp configuration in ~/.omp-ctl'
6arch=('x86_64' 'aarch64')
7url='https://github.com/moecly/omp-ctl'
8license=('custom')
9depends=('gtk3' 'webkit2gtk-4.1' 'libsoup3' 'glibc' 'gcc-libs')
10makedepends=('bun' 'cargo')
11source=("$pkgname-$pkgver.tar.gz::$url/archive/refs/tags/v$pkgver.tar.gz")
12sha256sums=('ba9e6cb2dded7e56ac339c823614b5aca89ffe109687fdab9e53d7f098105512')
13options=('!debug')
14
15build() {
16 cd "$pkgname-$pkgver"
17
18 # makepkg 的 -flto=auto 会把 C 依赖编成 GIMPLE-only 目标文件(只有 .gnu.lto 段),
19 # 而 rustc 现在默认用自带的 ld.lld 链接,liblto_plugin 物化不了它们,
20 # 表现为 ring 等 C 符号 undefined。Rust 侧 LTO 由 profile.release 的 lto=true 负责。
21 export CFLAGS="${CFLAGS//-flto=auto/}" CXXFLAGS="${CXXFLAGS//-flto=auto/}" LDFLAGS="${LDFLAGS//-flto=auto/}"
22
23 # 前端产物必须先生成:tauri::generate_context! 在编译期读取 ../dist。
24 # extra/bun 落后于仓库 web/bun.lock 的 lockfileVersion 2,读不了就退回自动解析。
25 (cd web && (bun install --frozen-lockfile || bun install) && bun run build)
26
27 # custom-protocol 不能省:tauri::is_dev() = !cfg!(feature = "custom-protocol"),
28 # 少了它编出来的是 dev 模式二进制,运行时去连 devUrl(127.0.0.1:1420)而不是内嵌前端,
29 # 装完打开就是「无法连接 127.0.0.1」。tauri CLI 的 tauri build 同样会加这一项。
30 cargo build --release --locked --features tauri/custom-protocol \
31 --manifest-path src-tauri/Cargo.toml
32}
33
34package() {
35 cd "$pkgname-$pkgver"
36
37 install -Dm755 target/release/omp-ctl "$pkgdir/usr/bin/omp-ctl"
38
39 install -Dm644 /dev/stdin "$pkgdir/usr/share/applications/omp-ctl.desktop" <<-'EOF'
40 [Desktop Entry]
41 Type=Application
42 Name=omp-ctl
43 Comment=Manage omp configuration in ~/.omp-ctl
44 Exec=omp-ctl
45 Icon=omp-ctl
46 Terminal=false
47 Categories=Utility;
48 StartupWMClass=omp-ctl
49 EOF
50
51 # 目录名必须是 hicolor/index.theme 里真实存在的尺寸,
52 # 否则 hicolor 主题不会索引这些图标(hicolor/32/apps 这类名字是无效的)。
53 local pair
54 for pair in 32x32:32x32 64x64:64x64 128x128:128x128 256x256:128x128@2x 512x512:icon; do
55 install -Dm644 "src-tauri/icons/${pair#*:}.png" \
56 "$pkgdir/usr/share/icons/hicolor/${pair%%:*}/apps/omp-ctl.png"
57 done
58}
59

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 08:09:03 Low 3
2026-10-06 08:02:16 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion