riftlift-bin

LOW
maintainer matheusvilano 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

The pip install only installs the project's own wheel from a GitHub release asset (official project infrastructure), not an external third-party package; the three SKIP'd checksums are for a desktop file, SVG icon, and a setup script (non-executed data or a local bundled file), which is sloppy but not dangerous. The prebuilt wheel and payload archives have pinned sha256 checksums and come from the project's own GitHub releases.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The pip install only installs the project's own wheel from a GitHub release asset (official project infrastructure), not an external third-party package; the three SKIP'd checksums are for a desktop file, SVG icon, and a setup script (non-executed data or a local bundled file), which is sloppy but not dangerous. The prebuilt wheel and payload archives have pinned sha256 checksums and come from the project's own GitHub releases.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium pip install of an external package pip_install_external

`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:46 "$_venv/bin/python" -m pip install --quiet --upgrade pip

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Matheus Vilano <aur.negotiate177@passinbox.com>
2pkgname=riftlift-bin
3pkgver=0.10.2.5
4pkgrel=1
5pkgdesc='Play owned Meta Rift and Oculus PC VR games on Linux'
6arch=('x86_64')
7url='https://github.com/Villagers654/RiftLift'
8license=('GPL-3.0-or-later')
9depends=('python')
10makedepends=('git')
11provides=('riftlift')
12conflicts=('riftlift')
13_tag="v${pkgver}"
14_base="https://github.com/Villagers654/RiftLift/releases/download/${_tag}"
15source=(
16 "${_base}/riftlift-${pkgver}-py3-none-any.whl"
17 "${_base}/riftlift-compat.zip"
18 "${_base}/riftlift-xrizer.tar.gz"
19 "${_base}/riftlift-dxvk.tar.gz"
20 "riftlift-setup"
21 "io.github.villagers654.RiftLift.desktop"
22 "io.github.villagers654.RiftLift.svg"
23)
24noextract=("riftlift-compat.zip" "riftlift-xrizer.tar.gz" "riftlift-dxvk.tar.gz")
25sha256sums=(
26 'e0acaecaa27769a84ed28a4f4cc28ed012b1834c7fce8e206fc813ff5f1a4653' # wheel
27 '602a2f95132f9cc0dc2ad1af97011e51591c6bab69f80f7980d9ca2c5efcdd83' # compat
28 '8fcd9dc9d417c37a67d75b06b8050598ee5ffd8a8426cf4b33e612c42135bb0e' # xrizer
29 '15d2625b9a7f0d01f5096c17211ff8e98ba238ddc0d39de03bb58c2277d7eedc' # dxvk
30 'SKIP'
31 'SKIP'
32 'SKIP'
33)
34
35prepare() {
36 : # nothing to prepare; payloads are consumed unextracted by 'riftlift setup'
37}
38
39package() {
40 local _venv="$pkgdir/usr/share/riftlift/venv"
41
42 # Mirror upstream install.sh: dedicated venv, pinned deps (incl. git dep),
43 # then force-reinstall the exact wheel over whatever a dependency dragged in.
44 install -dDm755 "$pkgdir/usr/share/riftlift"
45 python -m venv "$_venv"
46 "$_venv/bin/python" -m pip install --quiet --upgrade pip
47 "$_venv/bin/python" -m pip install --quiet --upgrade \
48 "$srcdir/riftlift-${pkgver}-py3-none-any.whl"
49 "$_venv/bin/python" -m pip install --quiet --force-reinstall --no-deps \
50 "$srcdir/riftlift-${pkgver}-py3-none-any.whl"
51
52 # venv was created under $pkgdir; scrub embedded build paths from shebangs.
53 local f
54 for f in "$_venv/bin/"*; do
55 if [[ -f $f && $(head -c 2 "$f") == '#!' ]]; then
56 sed -i "1s|$pkgdir||" "$f"
57 fi
58 done
59
60 # Launchers
61 install -dDm755 "$pkgdir/usr/bin"
62 ln -s "/usr/share/riftlift/venv/bin/riftlift" "$pkgdir/usr/bin/riftlift"
63 ln -s "/usr/share/riftlift/venv/bin/riftlift-gui" "$pkgdir/usr/bin/riftlift-gui"
64
65 # Desktop integration
66 install -Dm644 "$srcdir/io.github.villagers654.RiftLift.desktop" \
67 "$pkgdir/usr/share/applications/io.github.villagers654.RiftLift.desktop"
68 install -Dm644 "$srcdir/io.github.villagers654.RiftLift.svg" \
69 "$pkgdir/usr/share/icons/hicolor/scalable/apps/io.github.villagers654.RiftLift.svg"
70
71 # Offline compat payload consumption wrapper
72 install -Dm755 "$srcdir/riftlift-setup" "$pkgdir/usr/bin/riftlift-setup"
73 install -dDm755 "$pkgdir/usr/share/riftlift/payloads"
74 install -m644 "$srcdir/riftlift-compat.zip" "$pkgdir/usr/share/riftlift/payloads/"
75 install -m644 "$srcdir/riftlift-xrizer.tar.gz" "$pkgdir/usr/share/riftlift/payloads/"
76 install -m644 "$srcdir/riftlift-dxvk.tar.gz" "$pkgdir/usr/share/riftlift/payloads/"
77
78 install -Dm644 /dev/null "$pkgdir/usr/share/doc/riftlift/README"
79 cat >> "$pkgdir/usr/share/doc/riftlift/README" <<'EOF'
80First run: riftlift-setup
81Installs the pinned Proton/Meta/OpenXR/OpenVR/DXVK components from
82/usr/share/riftlift/payloads into your user data directory (~/.local/share/riftlift).
83No downloads occur; all payloads ship with the package.
84EOF
85}

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Medium 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion