snsdeck

maintainer zxp19821005 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The `npm add -D @electron-forge/plugin-local-electron` installs a package from the npm registry (not an unofficial/personal host). `@electron-forge/plugin-local-electron` is an official package from the electron-forge organization, published on the standard npm registry. Its purpose here is well-understood: it allows electron-forge to use a system-installed Electron binary instead of downloading one, which is exactly the pattern used by many AUR Electron packages to avoid bundling Electron. While it is not listed in package.json's devDependencies ahead of time (it gets added dynamically), it comes from the official npm registry and is a legitimate, well-known package. This is sloppy/non-standard packaging (the dependency should ideally be in package.json already), but it does not represent a genuine supply-chain threat from an unofficial host. The curl to ipinfo.io to detect CN geolocation and conditionally switch registries is mildly unusual but is a common pattern in AUR packages targeting Chinese users. Overall this is low severity — non-standard but not a real security risk.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 75%): The `npm add -D @electron-forge/plugin-local-electron` installs a package from the npm registry (not an unofficial/personal host). `@electron-forge/plugin-local-electron` is an official package from the electron-forge organization, published on the standard npm registry. Its purpose here is well-understood: it allows electron-forge to use a system-installed Electron binary instead of downloading one, which is exactly the pattern used by many AUR Electron packages to avoid bundling Electron. While it is not listed in package.json's devDependencies ahead of time (it gets added dynamically), it comes from the official npm registry and is a legitimate, well-known package. This is sloppy/non-standard packaging (the dependency should ideally be in package.json already), but it does not represent a genuine supply-chain threat from an unofficial host. The curl to ipinfo.io to detect CN geolocation and conditionally switch registries is mildly unusual but is a common pattern in AUR packages targeting Chinese users. Overall this is low severity — non-standard but not a real security risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:69 NODE_ENV=development npm add -D @electron-forge/plugin-local-electron

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=snsdeck
3pkgver=0.0.3
4_electronversion=26
5_nodeversion=20
6pkgrel=10
7pkgdesc="SNS Viewer like TweetDeck.(Use system-wide electron)"
8arch=('any')
9url="https://github.com/meganii/snsdeck"
10license=('MIT')
11conflicts=("${pkgname}")
12depends=(
13 "electron${_electronversion}"
14)
15makedepends=(
16 'gendesk'
17 'npm'
18 'nvm'
19 'curl'
20 'git'
21)
22source=(
23 "${pkgname}-${pkgver}::git+${url}#tag=v${pkgver}"
24 "${pkgname}.sh"
25)
26sha256sums=('7dbd5004b2fc8a2759d71be17cbc098c1b9f25c7defe593bf20644bf3c5b1295'
27 '291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
28_ensure_local_nvm() {
29 local NVM_DIR="${srcdir}/.nvm"
30 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
31 nvm install "${_nodeversion}"
32 nvm use "${_nodeversion}"
33}
34prepare() {
35 cd "${srcdir}/${pkgname}-${pkgver}"
36 sed -i -e "
37 s/@electronversion@/${_electronversion}/g
38 s/@appname@/${pkgname}/g
39 s/@runname@/app.asar/g
40 s/@cfgdirname@/${pkgname}/g
41 s/@options@//g
42 " "${srcdir}/${pkgname}.sh"
43 _ensure_local_nvm
44 gendesk -f -n -q \
45 --pkgname="${pkgname}" \
46 --pkgdesc="${pkgdesc}" \
47 --categories="Utility" \
48 --name="${pkgname}" \
49 --exec="${pkgname} %U"
50 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
51 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
52 HOME="${srcdir}/.electron-gyp"
53 {
54 echo -e '\n'
55 #echo 'build_from_source=true'
56 echo "cache=${srcdir}/.npm_cache"
57 echo "maxsockets=10"
58 } >> .npmrc
59 if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
60 {
61 echo 'registry=https://registry.npmmirror.com'
62 echo 'electron_mirror=https://registry.npmmirror.com/-/binary/electron/'
63 echo 'electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/'
64 } >> .npmrc
65 find ./ -type f -name "package-lock.json" -exec sed -i "s/registry.npmjs.org/registry.npmmirror.com/g" {} +
66 fi
67 sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
68 NODE_ENV=development npm install
69 NODE_ENV=development npm add -D @electron-forge/plugin-local-electron
70}
71build() {
72 cd "${srcdir}/${pkgname}-${pkgver}"
73 local electronDist="/usr/lib/electron${_electronversion}"
74 sed -i -e "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
75 {\\
76 name: \"@electron-forge/plugin-local-electron\",\\
77 config: {\\
78 electronPath: \"${electronDist}\"\\
79 }\\
80 }," forge.config.js
81 NODE_ENV=production npm run package
82}
83package() {
84 install -Dm755 "${srcdir}/${pkgname}.sh" "${pkgdir}/usr/bin/${pkgname}"
85 install -Dm644 "${srcdir}/${pkgname}-${pkgver}/out/${pkgname}-linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname}"
86 install -Dm644 "${srcdir}/${pkgname}-${pkgver}/${pkgname}.desktop" -t "${pkgdir}/usr/share/applications"
87 install -Dm644 "${srcdir}/${pkgname}-${pkgver}/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
88}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion