sable-next-git

MEDIUM
maintainer Thadah 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

The build process runs 'mise install' and 'mise run setup/tauri:setup' which download and execute unreviewed remote toolchains and dependencies (Rust, pnpm packages, CEF binaries) at build time via mise, and the source is a git repo from a non-standard self-hosted forge (git.sable.moe) with SKIP'd checksum; while this is the project's own infrastructure, the combination of arbitrary remote toolchain downloads via mise and unverifiable CEF binary fetching introduces meaningful supply-chain risk beyond a normal AUR build.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:29 source=("${pkgname}::git+https://git.sable.moe/SableClient/sable-next.git")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 60%): The build process runs 'mise install' and 'mise run setup/tauri:setup' which download and execute unreviewed remote toolchains and dependencies (Rust, pnpm packages, CEF binaries) at build time via mise, and the source is a git repo from a non-standard self-hosted forge (git.sable.moe) with SKIP'd checksum; while this is the project's own infrastructure, the combination of arbitrary remote toolchain downloads via mise and unverifiable CEF binary fetching introduces meaningful supply-chain risk beyond a normal AUR build.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: thadah <thadahdenyse@protonmail.com>
2pkgname=sable-next-git
3pkgver=nightly.1.22.10.nightly.261004132138.27df61cfed90
4pkgrel=1
5pkgdesc="Sable rewrite in Rust and Svelte"
6url=" https://next.sable.moe"
7license=('AGPL-3.0-or-later')
8arch=('x86_64')
9depends=(
10 'alsa-lib'
11 'gtk3'
12 'libcups'
13 'libpipewire'
14 'libxkbcommon'
15 'mesa'
16 'nspr'
17 'nss'
18)
19makedepends=(
20 'ccache'
21 'cmake'
22 'mise'
23 'xdotool'
24 'wget'
25)
26options=(!lto !debug)
27provides=('sable-next')
28conflicts=('sable-next')
29source=("${pkgname}::git+https://git.sable.moe/SableClient/sable-next.git")
30sha256sums=('SKIP')
31
32pkgver() {
33 cd "${pkgname}"
34 git describe --tags | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
35}
36
37build() {
38 cd "${pkgname}"
39
40 mise install
41 mise run setup # pnpm install + git hooks
42
43 mise run tauri:setup # Shared Rust/system dependencies, including Linux packages
44 mise run tauri:icons # Regenerate native icons after changing the logo SVG
45
46 # https://git.sable.moe/SableClient/sable-next/src/commit/d7fdf75ac807b76045b4d05056038822e08f7b46/.forgejo/workflows/tauri-build.yml#L256
47 mise exec -- pnpm tauri:cef build --config src-tauri/tauri.nightly.conf.json
48 mise run cef:package "${pkgver}" "Sable Next Nightly"
49}
50
51
52
53package() {
54 cd "${pkgname}/target/release/bundle/deb"
55
56 bsdtar -xf "sable-next-${pkgver}-linux-x86_64.deb" data.tar.gz
57 bsdtar -xf data.tar.gz -C "${pkgdir}/"
58
59 # Install license
60 install -Dm644 "${pkgdir}/opt/sable-next/CEF-LICENSE.txt" "${pkgdir}/usr/share/licenses/${pkgname}/CEF-LICENSE.txt"
61}
62

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Medium 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion