own3d-desktop-git
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 80%): The `yarn add -D @electron-forge/plugin-local-electron` installs a package from the official npm registry (npmjs.com). `@electron-forge/plugin-local-electron` is a legitimate, well-known package that is part of the official Electron Forge project (published by the Electron Forge team under the `@electron-forge` scoped namespace). It is used here for a standard purpose: pointing the build system at the system-installed Electron binary instead of downloading one. This is a common AUR pattern for packaging Electron apps against system Electron. The package is not from an unofficial or personal host, and it is not obfuscated or suspicious. The only real concern is that it is not pinned to a specific version, meaning a future malicious publish could affect builds — but this is a standard supply-chain hygiene issue (low severity), not an active threat. The rest of the PKGBUILD sources from the official GitHub repo with a git clone, uses nvm locally, and installs to standard paths. No binaries are fetched from unofficial hosts, no obfuscation is present, and no piracy or breakage is evident.
1 higher static finding superseded - not the current verdict (shown for transparency)
npm_install_external
Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.
-
PKGBUILD:83
NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
PKGBUILD
1 offending line(s) highlighted# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
pkgname=own3d-desktop-git
_pkgname='OWN3D Pro Desktop'
pkgver=2.6.0.r0.g18b92c9
_electronversion=29
_nodeversion=20
pkgrel=1
pkgdesc="Public Development Preview of the OWN3D Desktop App.(Use system-wide electron)"
arch=('any')
url="https://www.own3d.pro/"
_ghurl="https://github.com/own3d/desktop"
license=("MIT")
conflicts=("${pkgname%-git}")
provides=("${pkgname%-git}=${pkgver%.r*}")
depends=(
"electron${_electronversion}"
)
makedepends=(
'npm'
'git'
'nvm'
'gendesk'
'curl'
'yarn'
)
source=(
"${pkgname%-git}.git::git+${_ghurl}.git"
"${pkgname%-git}.sh"
)
sha256sums=('SKIP'
'f2fe8c189974ffb9d445e9a42bd4f1d5b60185607c3fcafae79ab44be224e013')
pkgver() {
cd "${srcdir}/${pkgname%-git}.git"
set -o pipefail
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
}
_ensure_local_nvm() {
local NVM_DIR="${srcdir}/.nvm"
source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
nvm install "${_nodeversion}"
nvm use "${_nodeversion}"
}
prepare() {
cd "${srcdir}/${pkgname%-git}.git"
sed -i -e "
s/@electronversion@/${_electronversion}/g
s/@appname@/${pkgname%-git}/g
s/@runname@/app.asar/g
s/@cfgdirname@/${_pkgname}/g
s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
" "${srcdir}/${pkgname%-git}.sh"
_ensure_local_nvm
gendesk -q -f -n \
--pkgname="${pkgname%-git}" \
--pkgdesc="${pkgdesc}" \
--categories="Game" \
--name="${_pkgname}" \
--exec="${pkgname%-git} %U"
export ELECTRON_SKIP_BINARY_DOWNLOAD=1
export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
HOME="${srcdir}/.electron-gyp"
mkdir -p "${srcdir}/.electron-gyp"
if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
{
echo -e '\n'
echo 'registry "https://registry.npmmirror.com"'
echo 'electron_mirror "https://registry.npmmirror.com/-/binary/electron/"'
echo 'electron_builder_binaries_mirror "https://registry.npmmirror.com/-/binary/electron-builder-binaries/"'
echo "cacheFolder "${srcdir}"/.yarn/cache"
echo "pluginsFolder "${srcdir}"/.yarn/plugins"
echo "globalFolder "${srcdir}"/.yarn/global"
echo 'useHardlinks true'
#echo 'buildFromSource true'
echo 'linkWorkspacePackages true'
echo 'fetchRetries 3'
echo 'fetchRetryTimeout 10000'
} >> .yarnrc
find ./ -type f -name "yarn.lock" -exec sed -i "s/registry.yarnpkg.com/registry.npmmirror.com/g" {} +
fi
sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
NODE_ENV=development yarn install --cache-folder "${srcdir}/.yarn_cache"
NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
}
build() {
cd "${srcdir}/${pkgname%-git}.git"
local electronDist="/usr/lib/electron${_electronversion}"
sed -i -e "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
{\\
name: \"@electron-forge/plugin-local-electron\",\\
config: {\\
electronPath: \"${electronDist}\"\\
}\\
}," forge.config.*
NODE_ENV=production yarn run package
}
package() {
install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
install -Dm644 "${srcdir}/${pkgname%-git}.git/out/prod/${_pkgname}-linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname%-git}"
install -Dm644 "${srcdir}/${pkgname%-git}.git/images/icon.png" "${pkgdir}/usr/share/pixmaps/${pkgname%-git}.png"
install -Dm644 "${srcdir}/${pkgname%-git}.git/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
install -Dm644 "${srcdir}/${pkgname%-git}.git/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |