openai-chatgpt

LOW
maintainer orphaned 0 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

Downloads official ChatGPT .deb packages directly from OpenAI's own CDN (persistent.oaistatic.com) with pinned SHA256 checksums; the flagged 'non-standard host' is plausibly OpenAI's own infrastructure, and the bundled 'OpenAI-Proprietary-Notice' is a local data file — no obfuscation, no remote code execution, no exfiltration.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): Downloads official ChatGPT .deb packages directly from OpenAI's own CDN (persistent.oaistatic.com) with pinned SHA256 checksums; the flagged 'non-standard host' is plausibly OpenAI's own infrastructure, and the bundled 'OpenAI-Proprietary-Notice' is a local data file — no obfuscation, no remote code execution, no exfiltration.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:62 source_x86_64=("https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_amd64.deb")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: WH-2099 <wh2099@pm.me>
2pkgname=openai-chatgpt
3pkgver=26.803.81509
4pkgrel=3
5pkgdesc="OpenAI's ChatGPT desktop app for Linux (preview)"
6arch=('x86_64' 'aarch64')
7url='https://chatgpt.com/download/'
8license=('LicenseRef-proprietary')
9depends=(
10 'alsa-lib'
11 'at-spi2-core'
12 'bash'
13 'cairo'
14 'coreutils'
15 'dbus'
16 'expat'
17 'gdk-pixbuf2'
18 'glib2'
19 'glibc'
20 'gtk3'
21 'libcups'
22 'libdrm'
23 'libgcc'
24 'libglvnd'
25 'libnotify'
26 'libstdc++'
27 'libusb'
28 'libx11'
29 'libxcb'
30 'libxcomposite'
31 'libxdamage'
32 'libxext'
33 'libxfixes'
34 'libxkbcommon'
35 'libxrandr'
36 'mesa'
37 'nspr'
38 'nss'
39 'pango'
40 'systemd-libs'
41 'tar'
42 'xdg-utils'
43 'xz'
44)
45depends_x86_64=(
46 'graphite'
47 'openssl'
48)
49optdepends=(
50 'apparmor: allow the Electron sandbox to use user namespaces when AppArmor is enabled'
51 'git: repository workflows'
52 'openssh: remote SSH workspaces'
53 'org.freedesktop.secrets: secure credential storage'
54 'pipewire: WebRTC desktop sharing under Wayland'
55)
56provides=("openai-chatgpt-bin=$pkgver")
57conflicts=('chatgpt')
58backup=('etc/apparmor.d/chatgpt')
59options=('!strip' '!debug')
60install='openai-chatgpt.install'
61source=('OpenAI-Proprietary-Notice')
62source_x86_64=("https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_amd64.deb")
63source_aarch64=("https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_arm64.deb")
64sha256sums=('45cffaa1435cab2a50b340850bb2e9684e8c561635d091465d576e5dcf679af5')
65sha256sums_x86_64=('a9bf91a368f9f7c4eea38082a9fb8fb46b8d005b719a6d7715d2e5a1982c38eb')
66sha256sums_aarch64=('f38fcc194eca9ab0327dc10c92340681eae77c5d75164df700384ce2adaccbc1')
67
68package() {
69 bsdtar --no-same-owner -xf data.tar.xz -C "$pkgdir" ./etc ./usr
70 install -Dm644 OpenAI-Proprietary-Notice "$pkgdir/usr/share/licenses/$pkgname/PROPRIETARY"
71}
72

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 3
2026-10-01 00:02:06 Low 3
2026-09-30 00:20:07 Low 3
2026-09-29 00:07:46 Low 3
2026-09-28 00:28:32 Low 3
2026-09-27 17:19:13 Medium 2
2026-09-27 00:07:07 Low 3
2026-09-26 00:12:15 Low 3
2026-09-25 00:03:36 Low 3
2026-09-24 00:24:14 Low 3
2026-09-23 00:28:13 Low 3
2026-09-22 00:15:14 Low 3
2026-09-21 00:26:32 Low 3
2026-09-20 00:25:31 Low 3
2026-09-19 00:25:36 Low 3
2026-09-18 11:28:26 Medium 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion