owasp-threat-dragon
maintainer orphaned
· 2 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The npx command runs electron-builder on the locally checked-out project source, which is a standard and safe build practice; the tool is not executing arbitrary remote code.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx command runs electron-builder on the locally checked-out project source, which is a standard and safe build practice; the tool is not executing arbitrary remote code.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
npx/bunx/deno executes a remote package
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:58
npx electron-builder build --linux --dir \
PKGBUILD
1 offending line(s) highlighted
1
# PKGBUILD
2
3
# Maintainer: Max Ulidtko <ulidtko@gmail.com>
4
pkgname=owasp-threat-dragon
5
pkgver=v1.2
6
pkgrel=3
7
pkgdesc="Electron Threat Modelling and diagramming tool by Mike Goodwin @ OWASP"
8
arch=('any')
9
url="https://threatdragon.org"
10
license=('Apache-2.0')
11
groups=()
12
depends=('electron5')
13
optdepends=('hunspell-en_US: spell checking')
14
makedepends=('git' 'npm' 'jq')
15
provides=("${pkgname%-git}")
16
conflicts=("${pkgname%-git}")
17
replaces=()
18
backup=()
19
options=()
20
install=
21
source=("${pkgname}::git+https://github.com/mike-goodwin/${pkgname}-desktop/#tag=${pkgver}"
22
threat-dragon
23
threat-dragon.desktop
24
relax-coverage-thresholds.patch
25
)
26
sha256sums=('SKIP'
27
'822d2385b2e781d105396ca2dea44990b65cbe2919b6c6afde67522be1ffcaab'
28
'ff6ea4a92aa33fe163e0618f89f334cbe8fee87e474baf769d2e921bc218b350'
29
'90e4d6d754d2cecc70cec11375e692ffd5e27cc310f269967dcb5c1df1f015e1')
30
31
pkgver() {
32
cd "$srcdir/${pkgname}"
33
git describe --tags
34
}
35
36
prepare() {
37
cd "$srcdir/${pkgname}"
38
patch -p1 -i "$srcdir/relax-coverage-thresholds.patch"
39
}
40
41
prune_absolute_paths() {
42
# somehow, sshpk package hardcodes absolute paths into its package.json
43
for module in sshpk; do
44
local target="node_modules/${module}/package.json"
45
jq 'del(.man)' "$target" >tmp.json
46
mv tmp.json "$target"
47
done
48
}
49
50
build() {
51
cd "$srcdir/${pkgname}"
52
npm install --no-audit --no-progress --no-fund
53
npm install --no-audit --no-progress --no-fund \
54
electron@"$(</usr/lib/electron5/version)"
55
prune_absolute_paths
56
npm run-script pretest
57
npm run-script build-content
58
npx electron-builder build --linux --dir \
59
--config electron-builder.json \
60
-c.electronDist=/usr/lib/electron5 \
61
-c.electronVersion="$(</usr/lib/electron5/version)"
62
}
63
64
check() {
65
cd "$srcdir/${pkgname}"
66
npm test
67
rm -rf coverage
68
}
69
70
package() {
71
install -Dm755 -t "${pkgdir}/usr/bin" "threat-dragon"
72
install -Dm644 -t "${pkgdir}/usr/share/applications" "threat-dragon.desktop"
73
install -Dm644 -t "${pkgdir}/usr/share/licenses/${pkgname}" "${pkgname}"/LICENSE.txt
74
75
cd "${pkgname}"
76
install -Dm644 "installers/linux-unpacked/resources/app.asar" "${pkgdir}/usr/share/${pkgname}.asar"
77
78
cd content/icons/png
79
for res in *x*.png; do
80
install -Dm644 "$res" \
81
"$pkgdir/usr/share/icons/hicolor/${res%.png}/apps/$pkgname.png"
82
done
83
}
84
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |