spotify-dev
The package downloads a prebuilt .deb from Spotify's official repository, which is a standard and expected source for the binary; while checksums are partially skipped, the build process validates the package hashes via the signed Release file, reducing supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt .deb from Spotify's official repository, which is a standard and expected source for the binary; while checksums are partially skipped, the build process validates the package hashes via the signed Release file, reducing supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:33
source=("${_pkgname}-Release::https://repository.spotify.com/dists/testing/Release"
PKGBUILD
1 offending line(s) highlighted# Maintainer: imp0 <jan <(a)> siteworld <(.)> be>
# Contributor: NicoHood <archlinux {cat} nicohood {dog} de>
# Contributor: Ashley Whetter <(firstname) @ awhetter.co.uk>
# Contributor: Eothred <yngve.levinsen@gmail.com>
pkgname=spotify-dev
_pkgname=spotify
pkgver=1.2.96.518
_commit=g366879e1
pkgrel=1
pkgdesc='A proprietary music streaming service'
arch=('x86_64')
license=('custom')
url='https://www.spotify.com'
depends=('alsa-lib'
'at-spi2-core'
'gtk3'
'libayatana-appindicator'
'libcurl-gnutls'
'libdbusmenu-glib'
'libglvnd'
'libice'
'libsm'
'nss'
'nspr'
'vulkan-icd-loader')
optdepends=('ffmpeg: Adds support for playback of local files'
'zenity: Adds support for importing local files'
'libnotify: Desktop notifications')
provides=("${_pkgname}")
conflicts=("${_pkgname}")
source=("${_pkgname}-Release::https://repository.spotify.com/dists/testing/Release"
"${_pkgname}-${pkgver}-${CARCH}.deb::https://repository.spotify.com/pool/non-free/s/spotify-client/spotify-client_${pkgver}.${_commit}_amd64.deb"
"${_pkgname}-${CARCH}-Packages::https://repository.spotify.com/dists/testing/non-free/binary-amd64/Packages"
'LICENSE')
sha512sums=('SKIP'
'98d25bd748258ca8b8357313cd35c7188bb0b26ed2d4390b0208473aa9fa3491a095559762f8ba06ec0828d73e05ee8fb488f0f357340191da4c65dd1f93c519'
'SKIP'
'2e16f7c7b09e9ecefaa11ab38eb7a792c62ae6f33d95ab1ff46d68995316324d8c5287b0d9ce142d1cf15158e61f594e930260abb8155467af8bc25779960615')
# Spotify uses different names for the arch
_SPOTIFY_ARCH=amd64
prepare() {
# Validate hashes from the "Release" file
echo "$(grep non-free/binary-${_SPOTIFY_ARCH}/Packages ${_pkgname}-Release | tail -n 2 | head -n 1 | awk '{print $1}') ${_pkgname}-${CARCH}-Packages" > "${_pkgname}-${CARCH}-Packages.sha256"
sha256sum -c "${_pkgname}-${CARCH}-Packages.sha256"
echo "$(grep SHA512 ${_pkgname}-${CARCH}-Packages | awk '{print $2}') ${_pkgname}-${pkgver}-${CARCH}.deb" > "${_pkgname}-${pkgver}-${CARCH}.deb.sha512"
sha512sum -c "${_pkgname}-${pkgver}-${CARCH}.deb.sha512"
}
build() {
tar -xzf data.tar.gz -C "${srcdir}"
}
package() {
# Install icons
install -D -m 644 "${srcdir}"/usr/share/spotify/spotify.desktop "${pkgdir}"/usr/share/applications/spotify.desktop
install -D -m 644 "${srcdir}"/usr/share/spotify/icons/spotify-linux-512.png "${pkgdir}"/usr/share/pixmaps/spotify-client.png
for size in 22 24 32 48 64 128 256 512; do
install -D -m 644 "${srcdir}/usr/share/spotify/icons/spotify-linux-$size.png" \
"${pkgdir}/usr/share/icons/hicolor/${size}x${size}/apps/spotify.png"
done
# Some vars to make life easier
_srcshare="${srcdir}/usr/share/${_pkgname}"
_pkgopt="${pkgdir}/opt/${_pkgname}"
# Create target directories
install -d -m 755 "${_pkgopt}"
install -d -m 755 "${_pkgopt}/Apps"
install -d -m 755 "${_pkgopt}/locales"
# Install files in rootdir
for _rfile in $(find "${_srcshare}" -maxdepth 1 -type f -name "*.pak" -o -name "*.dat" -o -name "*.bin" -o -name "libcef.so"); do
install -D -m 644 "${_rfile}" "${_pkgopt}"
done
# Install files in appdir
for _app in $(find "${_srcshare}/Apps" -maxdepth 1 -type f -name "*.spa"); do
install -D -m 644 "${_app}" "${_pkgopt}/Apps"
done
# Install locale data
for _loc in $(find "${_srcshare}/locales" -maxdepth 1 -type f -name "*.pak" -o -name "*.mo"); do
install -D -m 644 "${_loc}" "${_pkgopt}/locales"
done
# Install binary
install -D -m 755 "${_srcshare}/${_pkgname}" "${_pkgopt}"
# Symlink binary
install -d -m 755 "${pkgdir}"/usr/bin
ln -s /opt/spotify/spotify "${pkgdir}"/usr/bin/spotify
# Install license
# https://www.spotify.com/legal/end-user-agreement
install -D -m 644 "${srcdir}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |