sable-next-git
The build process runs 'mise install' and 'mise run setup/tauri:setup' which download and execute unreviewed remote toolchains and dependencies (Rust, pnpm packages, CEF binaries) at build time via mise, and the source is a git repo from a non-standard self-hosted forge (git.sable.moe) with SKIP'd checksum; while this is the project's own infrastructure, the combination of arbitrary remote toolchain downloads via mise and unverifiable CEF binary fetching introduces meaningful supply-chain risk beyond a normal AUR build.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:29
source=("${pkgname}::git+https://git.sable.moe/SableClient/sable-next.git")
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 60%): The build process runs 'mise install' and 'mise run setup/tauri:setup' which download and execute unreviewed remote toolchains and dependencies (Rust, pnpm packages, CEF binaries) at build time via mise, and the source is a git repo from a non-standard self-hosted forge (git.sable.moe) with SKIP'd checksum; while this is the project's own infrastructure, the combination of arbitrary remote toolchain downloads via mise and unverifiable CEF binary fetching introduces meaningful supply-chain risk beyond a normal AUR build.
PKGBUILD
1 offending line(s) highlighted# Maintainer: thadah <thadahdenyse@protonmail.com>
pkgname=sable-next-git
pkgver=nightly.1.22.10.nightly.261004132138.27df61cfed90
pkgrel=1
pkgdesc="Sable rewrite in Rust and Svelte"
url=" https://next.sable.moe"
license=('AGPL-3.0-or-later')
arch=('x86_64')
depends=(
'alsa-lib'
'gtk3'
'libcups'
'libpipewire'
'libxkbcommon'
'mesa'
'nspr'
'nss'
)
makedepends=(
'ccache'
'cmake'
'mise'
'xdotool'
'wget'
)
options=(!lto !debug)
provides=('sable-next')
conflicts=('sable-next')
source=("${pkgname}::git+https://git.sable.moe/SableClient/sable-next.git")
sha256sums=('SKIP')
pkgver() {
cd "${pkgname}"
git describe --tags | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
}
build() {
cd "${pkgname}"
mise install
mise run setup # pnpm install + git hooks
mise run tauri:setup # Shared Rust/system dependencies, including Linux packages
mise run tauri:icons # Regenerate native icons after changing the logo SVG
# https://git.sable.moe/SableClient/sable-next/src/commit/d7fdf75ac807b76045b4d05056038822e08f7b46/.forgejo/workflows/tauri-build.yml#L256
mise exec -- pnpm tauri:cef build --config src-tauri/tauri.nightly.conf.json
mise run cef:package "${pkgver}" "Sable Next Nightly"
}
package() {
cd "${pkgname}/target/release/bundle/deb"
bsdtar -xf "sable-next-${pkgver}-linux-x86_64.deb" data.tar.gz
bsdtar -xf data.tar.gz -C "${pkgdir}/"
# Install license
install -Dm644 "${pkgdir}/opt/sable-next/CEF-LICENSE.txt" "${pkgdir}/usr/share/licenses/${pkgname}/CEF-LICENSE.txt"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Medium | 3 |
| 2026-10-06 00:13:36 | Low | 3 |
| 2026-10-05 23:40:58 | Medium | 2 |