orangplayer-bin
The package downloads a prebuilt binary from the project's official GitHub release page, which is a common and generally safe practice; the low severity is due to the lack of source build and limited AUR votes, not malicious indicators.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads a prebuilt binary from the project's official GitHub release page, which is a common and generally safe practice; the low severity is due to the lack of source build and limited AUR votes, not malicious indicators.
PKGBUILD
pkgname=orangplayer-bin
pkgver=0.1.1
pkgrel=2
pkgdesc="Media player for your files, YouTube, YT Music, SoundCloud and Spotify, with lyrics, downloads and skins"
arch=('x86_64')
url="https://github.com/Orang-Studio/OrangPlayer"
license=('GPL-3.0-or-later')
depends=('qt6-base' 'qt6-declarative' 'qt6-svg' 'taglib' 'ffmpeg>=2:9' 'ffmpeg<2:10' 'yt-dlp' 'libplacebo' 'libass' 'luajit' 'lcms2'
'uchardet' 'zimg' 'libpulse' 'libpipewire' 'alsa-lib' 'sndio' 'libva' 'libvdpau' 'libdrm' 'libdisplay-info'
'mesa' 'libglvnd' 'vulkan-icd-loader' 'wayland' 'libxkbcommon' 'libx11' 'libxext' 'libxfixes' 'libxpresent'
'libxrandr' 'libxss' 'libxv' 'libjpeg-turbo' 'zlib' 'openssl' 'hicolor-icon-theme')
optdepends=('noto-fonts-cjk: Chinese, Japanese and Korean lyrics and titles'
'cava: visualizer bars'
'discord: Rich Presence')
provides=('orangplayer')
conflicts=('orangplayer' 'orang-player')
options=('!strip' '!debug')
source=("$url/releases/download/v$pkgver/orangplayer-$pkgver-x86_64.tar.zst")
sha256sums=('07c844755c37f2c66f75c07000139d6e82328f42875bec5e138f82f85eb2d59a')
package() {
cp -a usr "$pkgdir/"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:13:36 | Low | 2 |
| 2026-10-05 23:40:58 | Low | 2 |