snippit-bin

MEDIUM
maintainer mikili 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package installs a prebuilt binary from a GitHub release, which is an unverifiable executable from a potentially swappable host, creating a supply-chain risk if the source were compromised.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 95%): The package installs a prebuilt binary from a GitHub release, which is an unverifiable executable from a potentially swappable host, creating a supply-chain risk if the source were compromised.

PKGBUILD

1# Maintainer: mikilimj <milosz@medportal.pl>
2# pkgver is bumped automatically by .github/workflows/build.yml on each
3# GitHub release; checksums are refreshed there with updpkgsums.
4pkgname=snippit-bin
5pkgver=1.2.2
6pkgrel=1
7pkgdesc="Desktop clip-trimming tool with live multi-track audio mixing and lossless export (prebuilt binary)"
8arch=('x86_64')
9url="https://github.com/mikilimj/Snippit"
10license=('LicenseRef-proprietary')
11depends=('webkit2gtk-4.1' 'gtk3' 'libayatana-appindicator' 'ffmpeg' 'rclone'
12 'gst-plugins-good' 'gst-libav' 'hicolor-icon-theme')
13provides=('snippit')
14conflicts=('snippit')
15source=("$url/releases/download/v$pkgver/Snippit_${pkgver}_amd64.deb")
16sha256sums=('c1ebc40351524e0000749c463d3e3c547c7b17c2deecf0f1daa370a1cd43996b')
17
18package() {
19 # makepkg has already unpacked the .deb (an ar archive) into $srcdir;
20 # unpack its payload and drop the bundled sidecars — the app resolves
21 # them next to /usr/bin/snippit, where the system packages provide them.
22 bsdtar -xf "$srcdir"/data.tar.* -C "$pkgdir"
23 rm -f "$pkgdir"/usr/bin/{ffmpeg,ffprobe,rclone}
24 chmod -R u+rwX,go+rX,go-w "$pkgdir/usr"
25}
26

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Medium 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion