opencode-desktop-v1-bin

LOW
maintainer lapsus 0 votes scanned 2026-10-08 20:09:40.002650
View on AUR
Why flagged

The package installs a prebuilt Electron app from GitHub releases, which is normal for AUR binary packages; the source is verifiable, checksummed, and the build process is transparent and safe, with no remote code execution or obfuscation.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt Electron app from GitHub releases, which is normal for AUR binary packages; the source is verifiable, checksummed, and the build process is transparent and safe, with no remote code execution or obfuscation.

PKGBUILD

1# Maintainer: Yakov Till <yakov.till@gmail.com>
2
3pkgname=opencode-desktop-v1-bin
4pkgver=1.18.35
5pkgrel=1
6pkgdesc="OpenCode desktop client (1.x release line)"
7arch=('x86_64' 'aarch64')
8url="https://opencode.ai"
9license=('MIT')
10provides=('opencode-desktop')
11conflicts=('opencode-desktop' 'opencode-desktop-bin')
12# Upstream publishes the 1.x desktop only as GitHub release assets, while the
13# opencode.ai mirror that backs opencode-desktop-bin carries the 2.x line alone.
14# The two packages therefore track separate release channels and never merge.
15_electron=electron42
16depends=('ripgrep')
17depends_x86_64=("${_electron}")
18# Arch Linux ARM ships no electron package at all (which is also why official
19# code is absent there), so only x86_64 can run on a system runtime. aarch64 keeps
20# the bundled one and so has to carry its dependencies: of the 23 packages the
21# bundled binary links against, gtk3, nss and alsa-lib are the only ones nothing
22# else pulls, and libpulse is dlopen'd rather than linked — invisible to that
23# reading, but it is what Chromium plays audio through.
24depends_aarch64=('gtk3' 'nss' 'libxss' 'libxtst' 'alsa-lib' 'libsecret' 'libnotify' 'xdg-utils'
25 'libpulse')
26optdepends=('libappindicator-gtk3: tray icon support')
27# Prebuilt payload: never publish -debug split packages for binaries we did not
28# compile. Strip stays at the builder default — unlike opencode-desktop-bin there
29# is no bundled CLI whose embedded bundle a strip would discard (the server runs
30# in-process here, and the v2 sidecar path that wants a CLI is opt-in through
31# OPENCODE_SIDECAR_V2=1), and the only ELF files left to strip are the native
32# addons, whose export tables strip --strip-unneeded leaves byte-identical.
33options=('!debug')
34
35latestver() {
36 # The 1.x line keeps its own release stream, so the newest v1.* release is the
37 # version source even once 2.x starts publishing releases of its own.
38 curl -fsSL 'https://api.github.com/repos/anomalyco/opencode/releases?per_page=100' |
39 jq -r 'first(.[] | .tag_name | select(startswith("v1."))) | ltrimstr("v")'
40}
41
42source=("LICENSE::https://raw.githubusercontent.com/anomalyco/opencode/v${pkgver}/LICENSE")
43source_x86_64=("${pkgname}-${pkgver}-linux-amd64.deb::https://github.com/anomalyco/opencode/releases/download/v${pkgver}/opencode-desktop-linux-amd64.deb")
44source_aarch64=("${pkgname}-${pkgver}-linux-arm64.deb::https://github.com/anomalyco/opencode/releases/download/v${pkgver}/opencode-desktop-linux-arm64.deb")
45sha256sums=('625f0f619133f89bbbb2abe37369613dfa1885eba1e50d02170deb62bb42cb6b')
46sha256sums_x86_64=('2243bff81e3ac08605fe8a2aff022f3f581cfd2ef07136a3f7cc32cb9fc74fa6')
47sha256sums_aarch64=('6c3f87e48b9dc53042aa9e850c055ec92a2ec893b3295673a93bf265ed7e5f75')
48
49package() {
50 local _debarch=amd64
51 [[ "${CARCH}" == aarch64 ]] && _debarch=arm64
52 bsdtar -xf "${srcdir}/${pkgname}-${pkgver}-linux-${_debarch}.deb" data.tar.xz
53 bsdtar -xf data.tar.xz -C "${pkgdir}"
54
55 local _appdir _exec
56 if [[ "${CARCH}" == x86_64 ]]; then
57 # The app only has to work on the Electron it was built against, so refuse
58 # to package a runtime pairing upstream never shipped.
59 local _bundled
60 _bundled=$(grep -aoP 'Electron/\K[0-9]+' "${pkgdir}/opt/OpenCode/ai.opencode.desktop" | head -1)
61 if [[ "electron${_bundled}" != "${_electron}" ]]; then
62 echo "Upstream now bundles Electron ${_bundled:-<undetected>}; set _electron=electron${_bundled}" >&2
63 exit 1
64 fi
65
66 # Keep the app payload only; the bundled Chromium/Node runtime is replaced by
67 # the system electron, which ships its own sandbox, codecs and ICU data. The
68 # payload is laid out flat because electron resolves the asar path itself but
69 # not a directory holding nothing but app.asar.
70 _appdir="${pkgdir}/usr/lib/opencode-desktop-v1"
71 install -d "${_appdir}"
72 mv "${pkgdir}/opt/OpenCode/resources/app.asar" \
73 "${pkgdir}/opt/OpenCode/resources/app.asar.unpacked" "${_appdir}/"
74 rm -rf "${pkgdir}/opt"
75 _exec="${_electron} /usr/lib/opencode-desktop-v1/app.asar"
76 else
77 _appdir="${pkgdir}/opt/OpenCode/resources"
78 _exec="/opt/OpenCode/ai.opencode.desktop"
79 fi
80
81 # A distro package must never self-update, and the shipped apparmor profile only
82 # applies to Ubuntu's AppArmor setup.
83 rm -f "${_appdir}/app-update.yml" "${_appdir}/apparmor-profile"
84 rm -rf "${pkgdir}/usr/share/doc"
85
86 # Prune musl native modules (useless on glibc Arch)
87 find "${_appdir}" -name '*.musl.node' -delete
88 find "${_appdir}" -depth -type d -name '*-musl' -exec rm -rf {} +
89
90 # Launcher script (supports user flags and Wayland)
91 install -Dm755 /dev/stdin "${pkgdir}/usr/bin/opencode-desktop" <<'EOF'
92#!/bin/bash
93XDG_CONFIG_HOME="${XDG_CONFIG_HOME:-$HOME/.config}"
94if [[ -f "$XDG_CONFIG_HOME/opencode-desktop-flags.conf" ]]; then
95 OPENCODE_USER_FLAGS="$(grep -v '^#' "$XDG_CONFIG_HOME/opencode-desktop-flags.conf")"
96fi
97exec @EXEC@ $OPENCODE_USER_FLAGS "$@"
98EOF
99 sed -i "s|@EXEC@|${_exec}|" "${pkgdir}/usr/bin/opencode-desktop"
100
101 # Upstream's entries launch the bundled build; point both at the wrapper instead
102 sed -i 's|Exec=/opt/OpenCode/ai\.opencode\.desktop|Exec=opencode-desktop|' \
103 "${pkgdir}"/usr/share/applications/*.desktop
104
105 install -Dm644 "${srcdir}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
106}

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 20:09:40 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion