photon-studio

LOW
maintainer duanluan 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Downloads a prebuilt AppImage from downloads.tenzen.studio, which appears to be the project's own official download infrastructure matching the declared url and pkgname; the checksum is provided and non-SKIP, so the binary is verifiable; the main risk is trusting a relatively unknown vendor's proprietary software, not a supply-chain substitution attack.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Downloads a prebuilt AppImage from downloads.tenzen.studio, which appears to be the project's own official download infrastructure matching the declared url and pkgname; the checksum is provided and non-SKIP, so the binary is verifiable; the main risk is trusting a relatively unknown vendor's proprietary software, not a supply-chain substitution attack.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:50 "photon-studio-${pkgver}-x86_64.AppImage::https://downloads.tenzen.studio/photon/stable/linux/${pkgver}/Photon-Studio-${pkgver}-linux-x64.AppImage"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: duanluan <duanluan@outlook.com>
2
3# Naming: Photon Studio is non-free software without available sources, so per
4# the Arch nonfree packaging guidelines the -bin suffix must not be used.
5# See docs/aur-packaging-rules.md in the source repository.
6pkgname=photon-studio
7pkgver=0.1.42
8pkgrel=1
9pkgdesc='Offline image editor with Photoshop-equivalent capabilities and native PSD support'
10arch=('x86_64')
11url='https://tenzen.studio/photon/'
12license=('LicenseRef-Proprietary')
13depends=(
14 'alsa-lib'
15 'at-spi2-core'
16 'cairo'
17 'dbus'
18 'expat'
19 'gcc-libs'
20 'glib2'
21 'glibc'
22 'gtk3'
23 'hicolor-icon-theme'
24 'libcups'
25 'libnotify'
26 'libsecret'
27 'libx11'
28 'libxcb'
29 'libxcomposite'
30 'libxdamage'
31 'libxext'
32 'libxfixes'
33 'libxkbcommon'
34 'libxrandr'
35 'libxss'
36 'libxtst'
37 'mesa'
38 'nspr'
39 'nss'
40 'pango'
41 'systemd-libs'
42 'util-linux'
43 'util-linux-libs'
44 'xdg-utils'
45)
46provides=("photon-studio-bin=${pkgver}")
47conflicts=('photon-studio-bin')
48options=('!strip' '!lto')
49source=(
50 "photon-studio-${pkgver}-x86_64.AppImage::https://downloads.tenzen.studio/photon/stable/linux/${pkgver}/Photon-Studio-${pkgver}-linux-x64.AppImage"
51 'photon-studio.desktop'
52 'photon-studio.sh'
53 'photon-studio.png'
54)
55sha256sums=(
56 'ee000c70569440c7f6c191b1393d8d3315a231ac7e835122532b76bf8f5bd841'
57 '29ec994ac0ffd028dbc0a86e4a1df1d25dc0de8988458cb0f579a1330ffd5f5d'
58 '3dbdf2ebbc5979699219a3d332245a19ab0409f21185a886efd92f8bcdc65969'
59 'd49bb3c106257c1f75995fa793737113dc87418be5bec19388e6a523ffaafc18'
60)
61
62package() {
63 cd "${srcdir}"
64
65 chmod +x "${srcdir}/photon-studio-${pkgver}-x86_64.AppImage"
66 "${srcdir}/photon-studio-${pkgver}-x86_64.AppImage" --appimage-extract >/dev/null
67
68 local approot="${srcdir}/squashfs-root"
69 for required_path in \
70 "${approot}/AppRun" \
71 "${approot}/photon-studio.bin" \
72 "${approot}/resources/app.asar"; do
73 [[ -e "${required_path}" ]] || {
74 printf 'missing required upstream path: %s\n' "${required_path}" >&2
75 return 1
76 }
77 done
78
79 install -dm755 "${pkgdir}/opt/${pkgname}"
80 cp -a "${approot}/." "${pkgdir}/opt/${pkgname}/"
81
82 # Electron's sandbox helper must retain its setuid bit for sandboxed renderers.
83 chmod 4755 "${pkgdir}/opt/${pkgname}/chrome-sandbox"
84
85 install -Dm755 "${srcdir}/photon-studio.sh" \
86 "${pkgdir}/usr/bin/photon-studio"
87 install -Dm644 "${srcdir}/photon-studio.desktop" \
88 "${pkgdir}/usr/share/applications/photon-studio.desktop"
89 # Official brand logo (https://tenzen.studio/assets/brand/photon-logo.png,
90 # already 512x512). Installed into 512x512 because hicolor's index.theme
91 # declares no 1024x1024 directory, so icons placed there are never found.
92 install -Dm644 "${srcdir}/photon-studio.png" \
93 "${pkgdir}/usr/share/icons/hicolor/512x512/apps/photon-studio.png"
94
95 install -Dm644 "${approot}/LICENSE.electron.txt" \
96 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.electron.txt"
97 install -Dm644 "${approot}/LICENSES.chromium.html" \
98 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSES.chromium.html"
99}
100

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion