piped-frontend-git

maintainer 30p87 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The flagged 'pnpm install vite' commands are part of the build process for the project's own frontend from its official source repository, not installation of an undeclared external package with malicious intent; this is normal behavior for building a JavaScript project.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The flagged 'pnpm install vite' commands are part of the build process for the project's own frontend from its official source repository, not installation of an undeclared external package with malicious intent; this is normal behavior for building a JavaScript project.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:34 if pnpm install vite; then :; fi
  • PKGBUILD:36 pnpm install vite

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: 30p87 <aur@30p87.de>
2
3pkgname='piped-frontend-git'
4_componentname="${pkgname%'-git'}"
5_componentnameshort="${_componentname#'piped-'}"
6pkgver=r4906.da7ab35
7pkgrel=1
8pkgdesc='An alternative privacy-friendly YouTube frontend which is efficient by design. Frontend component, calling [piped-backend-git](https://aur.archlinux.org/piped-backend-git) for Metadata'
9arch=('x86_64')
10url='https://github.com/TeamPiped/Piped'
11license=('AGPL-3.0')
12groups=('piped-git')
13makedepends=('git' 'pnpm')
14install=piped-frontend.install
15source=("git+${url}"
16 'configure-piped-frontend.sh'
17 'config.properties')
18sha256sums=('SKIP'
19 'ea0d3bb44c46223b8fbbfe06a5397ee103d77a74f6e29ed636d02bbfebe0f77a'
20 '7e310112487f7a77b5fe7b5721e6f077edaeda8009b3881f39dee2ee584e1922')
21dest="/usr/share/webapps/piped/${_componentnameshort}"
22
23pkgver() {
24 cd Piped
25 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
26}
27
28prepare() {
29 sed -i "s|/usr/share/nginx/html|${dest}|g" "${srcdir}/Piped/docker/nginx.conf"
30}
31
32build() {
33 cd Piped
34 if pnpm install vite; then :; fi
35 pnpm approve-builds core-js esbuild vue-demi
36 pnpm install vite
37 pnpm run build
38}
39
40package() {
41 install -dm755 "${pkgdir}/etc/webapps/piped"
42
43 install -Dm644 "${srcdir}/Piped/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
44 install -Dm644 "${srcdir}/Piped/docker/nginx.conf" "${pkgdir}/usr/share/doc/piped/${_componentnameshort}/nginx.conf"
45 install -Dm644 "${srcdir}/config.properties" "${pkgdir}/usr/share/doc/piped/${_componentnameshort}/config.properties"
46
47 install -dm755 "${pkgdir}${dest}"
48 cp -ra ${srcdir}/Piped/dist/* "${pkgdir}${dest}"
49 chmod -R 755 "${pkgdir}${dest}"
50 install -Dm755 "${srcdir}/configure-piped-frontend.sh" "${pkgdir}/usr/bin/configure-piped-frontend"
51}
52

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion