openai-chatgpt
Downloads official ChatGPT .deb packages directly from OpenAI's own CDN (persistent.oaistatic.com) with pinned SHA256 checksums; the flagged 'non-standard host' is plausibly OpenAI's own infrastructure, and the bundled 'OpenAI-Proprietary-Notice' is a local data file — no obfuscation, no remote code execution, no exfiltration.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): Downloads official ChatGPT .deb packages directly from OpenAI's own CDN (persistent.oaistatic.com) with pinned SHA256 checksums; the flagged 'non-standard host' is plausibly OpenAI's own infrastructure, and the bundled 'OpenAI-Proprietary-Notice' is a local data file — no obfuscation, no remote code execution, no exfiltration.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:62
source_x86_64=("https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_amd64.deb")
PKGBUILD
1 offending line(s) highlighted# Maintainer: WH-2099 <wh2099@pm.me>
pkgname=openai-chatgpt
pkgver=26.803.81509
pkgrel=3
pkgdesc="OpenAI's ChatGPT desktop app for Linux (preview)"
arch=('x86_64' 'aarch64')
url='https://chatgpt.com/download/'
license=('LicenseRef-proprietary')
depends=(
'alsa-lib'
'at-spi2-core'
'bash'
'cairo'
'coreutils'
'dbus'
'expat'
'gdk-pixbuf2'
'glib2'
'glibc'
'gtk3'
'libcups'
'libdrm'
'libgcc'
'libglvnd'
'libnotify'
'libstdc++'
'libusb'
'libx11'
'libxcb'
'libxcomposite'
'libxdamage'
'libxext'
'libxfixes'
'libxkbcommon'
'libxrandr'
'mesa'
'nspr'
'nss'
'pango'
'systemd-libs'
'tar'
'xdg-utils'
'xz'
)
depends_x86_64=(
'graphite'
'openssl'
)
optdepends=(
'apparmor: allow the Electron sandbox to use user namespaces when AppArmor is enabled'
'git: repository workflows'
'openssh: remote SSH workspaces'
'org.freedesktop.secrets: secure credential storage'
'pipewire: WebRTC desktop sharing under Wayland'
)
provides=("openai-chatgpt-bin=$pkgver")
conflicts=('chatgpt')
backup=('etc/apparmor.d/chatgpt')
options=('!strip' '!debug')
install='openai-chatgpt.install'
source=('OpenAI-Proprietary-Notice')
source_x86_64=("https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_amd64.deb")
source_aarch64=("https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_arm64.deb")
sha256sums=('45cffaa1435cab2a50b340850bb2e9684e8c561635d091465d576e5dcf679af5')
sha256sums_x86_64=('a9bf91a368f9f7c4eea38082a9fb8fb46b8d005b719a6d7715d2e5a1982c38eb')
sha256sums_aarch64=('f38fcc194eca9ab0327dc10c92340681eae77c5d75164df700384ce2adaccbc1')
package() {
bsdtar --no-same-owner -xf data.tar.xz -C "$pkgdir" ./etc ./usr
install -Dm644 OpenAI-Proprietary-Notice "$pkgdir/usr/share/licenses/$pkgname/PROPRIETARY"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 3 |
| 2026-10-01 00:02:06 | Low | 3 |
| 2026-09-30 00:20:07 | Low | 3 |
| 2026-09-29 00:07:46 | Low | 3 |
| 2026-09-28 00:28:32 | Low | 3 |
| 2026-09-27 17:19:13 | Medium | 2 |
| 2026-09-27 00:07:07 | Low | 3 |
| 2026-09-26 00:12:15 | Low | 3 |
| 2026-09-25 00:03:36 | Low | 3 |
| 2026-09-24 00:24:14 | Low | 3 |
| 2026-09-23 00:28:13 | Low | 3 |
| 2026-09-22 00:15:14 | Low | 3 |
| 2026-09-21 00:26:32 | Low | 3 |
| 2026-09-20 00:25:31 | Low | 3 |
| 2026-09-19 00:25:36 | Low | 3 |
| 2026-09-18 11:28:26 | Medium | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |