pen-dev-appimage
The package downloads prebuilt AppImages from the project's official GitHub releases, which is a normal distribution method; the AppImages are not executed during build but are installed as-is, and all sources are properly checksummed, making the risk low despite the AppImage format's usual opacity.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads prebuilt AppImages from the project's official GitHub releases, which is a normal distribution method; the AppImages are not executed during build but are installed as-is, and all sources are properly checksummed, making the risk low despite the AppImage format's usual opacity.
PKGBUILD
# Maintainer: Arnaud Gissinger <agissing@student.42.fr>
pkgname=pen-dev-appimage
pkgver=1.2.14
pkgrel=1
pkgdesc='Pen: AI-powered design canvas (formerly Pencil) (appimage)'
arch=('x86_64' 'aarch64')
url='https://www.pen.dev'
license=('LicenseRef-Pen-EULA')
provides=("pen-dev=$pkgver" "pencil-dev=$pkgver")
conflicts=('pen-dev' 'pen-dev-bin' 'pencil-dev' 'pencil-dev-bin' 'pencil-dev-appimage')
options=('!strip' '!debug')
depends=('fuse2' 'glibc' 'hicolor-icon-theme' 'zlib')
makedepends=('python' 'squashfs-tools')
_release="https://github.com/highagency/pen-desktop-releases/releases/download/v${pkgver}"
source=('pen-dev.desktop' 'pen-dev.png' 'LICENSE' 'extract-appimage.py')
sha256sums=(
'8d8a5cacedc15daea8974cbf6e33edaace4b9542a2117cf1df082dd413a00138'
'5898e0189970c8995fc14978ad9b91483d787d2842a01369e29da928b49cc75a'
'42b82acedd61dfb095f44aaadbc58b703fabaa1c25d60b6e133231a0c70c8c53'
'c488ed6256fd9663637e95d5e5e8632b523d22e5f873145c76ccf016d409081d'
)
source_x86_64=("${_release}/Pen-${pkgver}-linux-x86_64.AppImage")
sha256sums_x86_64=('512ee5eea9797aacee452f9569b54d875c6c3a49f397700d906b9a82f633411b')
source_aarch64=("${_release}/Pen-${pkgver}-linux-arm64.AppImage")
sha256sums_aarch64=('3a19cbf95cf9ce123047d08128df19f32b82eb2cde6f7faeb54bc670f528ad85')
noextract=("Pen-${pkgver}-linux-x86_64.AppImage" "Pen-${pkgver}-linux-arm64.AppImage")
prepare() {
local upstream_arch=x86_64
[[ $CARCH == aarch64 ]] && upstream_arch=arm64
rm -rf "$srcdir/squashfs-root"
python "$srcdir/extract-appimage.py" "Pen-$pkgver-linux-$upstream_arch.AppImage" "$srcdir/squashfs-root"
}
package() {
local upstream_arch=x86_64 mcp_arch=x64
if [[ $CARCH == aarch64 ]]; then
upstream_arch=arm64
mcp_arch=arm64
fi
install -Dm755 "$srcdir/Pen-$pkgver-linux-$upstream_arch.AppImage" "$pkgdir/opt/pen-dev-appimage/pen-dev.AppImage"
install -d "$pkgdir/usr/bin"
# Match upstream's AppImage desktop launcher; pass all user arguments through.
cat > "$pkgdir/usr/bin/pen-dev" <<'LAUNCHER'
#!/bin/sh
exec /opt/pen-dev-appimage/pen-dev.AppImage --no-sandbox "$@"
LAUNCHER
chmod 755 "$pkgdir/usr/bin/pen-dev"
ln -s pen-dev "$pkgdir/usr/bin/pencil-dev"
install -Dm755 "$srcdir/squashfs-root/resources/app.asar.unpacked/out/mcp-server-linux-$mcp_arch" "$pkgdir/opt/pen-dev-appimage/mcp-server"
install -Dm644 "$srcdir/pen-dev.desktop" "$pkgdir/usr/share/applications/pen-dev.desktop"
install -Dm644 "$srcdir/pen-dev.png" "$pkgdir/usr/share/icons/hicolor/512x512/apps/pen-dev.png"
install -Dm644 "$srcdir/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-28 11:20:45 | Low | 2 |