spacedrive-git
The use of 'bunx tauri build' executes a project-local development tool during build; it runs within the source tree and does not fetch or execute unreviewed remote code, posing minimal risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The use of 'bunx tauri build' executes a project-local development tool during build; it runs within the source tree and does not fetch or execute unreviewed remote code, posing minimal risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:39
(cd apps/tauri && bunx tauri build --no-bundle -- --no-default-features)
PKGBUILD
1 offending line(s) highlighted# Maintainer: Shohei Maruyama <cheat.sc.linux@outlook.com>
pkgname='spacedrive-git'
pkgver=r4800.4d87617
pkgrel=1
pkgdesc='Spacedrive is an open source cross-platform file explorer, powered by a virtual distributed filesystem written in Rust.'
arch=('x86_64')
url='https://spacedrive.com/'
license=('AGPL3')
source=('spacedrive::git+https://github.com/spacedriveapp/spacedrive.git')
depends=('ffmpeg' 'libheif' 'gtk3' 'webkit2gtk-4.1' 'pango' 'gdk-pixbuf2' 'cairo' 'libsoup' 'glib2' 'xdotool')
conflicts=('spacedrive')
makedepends=('cargo' 'bun' 'git' 'clang' 'mold')
sha256sums=('SKIP')
options=(!lto)
pkgver() {
cd "${pkgname%-git}"
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
}
prepare() {
cd "${pkgname%-git}"
cargo fetch --locked --target $(rustc --print host-tuple)
bun install
}
build() {
cd "${pkgname%-git}"
export CARGO_TARGET_DIR=target
export RUSTFLAGS+=' -Clinker=clang -Clink-arg=-fuse-ld=mold'
export CC=clang
export LDFLAGS+=' -fuse-ld=mold'
cargo build --release --package sd-core --bin sd-daemon --no-default-features
(cd apps/tauri && bunx tauri build --no-bundle -- --no-default-features)
}
package() {
cd "${pkgname%-git}"
install -Dm0755 "apps/tauri/src-tauri/target/release/Spacedrive" "${pkgdir}/usr/bin/spacedrive"
install -Dm0755 -t "${pkgdir}/usr/bin/" target/release/sd-daemon
install -Dm0755 -t "${pkgdir}/usr/share/licenses/${pkgname}/" LICENSE
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |