stable-diffusion.cpp-vulkan-bin
MEDIUM
maintainer monsoon235
0 votes
scanned 2026-10-06 08:02:16.298752
Why flagged
Installs prebuilt binaries from a GitHub release, which are unverifiable and could be silently swapped, posing a supply-chain risk despite being from a plausible project-owned source.
Triggered rules
Low
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
Medium
AI review of an ambiguous pattern
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 95%): Installs prebuilt binaries from a GitHub release, which are unverifiable and could be silently swapped, posing a supply-chain risk despite being from a plausible project-owned source.
PKGBUILD
1
# Maintainer: monsoon <29970829+monsoon235@users.noreply.github.com>
2
pkgname=stable-diffusion.cpp-vulkan-bin
3
pkgver=master_929_3f8527a
4
pkgrel=1
5
pkgdesc='stable-diffusion.cpp upstream Linux x86_64 prebuilt binaries with the Vulkan backend'
6
arch=('x86_64')
7
url='https://github.com/leejet/stable-diffusion.cpp'
8
license=('MIT')
9
depends=('glibc' 'gcc-libs' 'vulkan-icd-loader')
10
provides=('stable-diffusion.cpp')
11
conflicts=('stable-diffusion.cpp' 'stable-diffusion.cpp-git' 'stable-diffusion.cpp-rocm-bin')
12
options=('!strip' '!debug')
13
_upstream_tag=master-929-3f8527a
14
_commit=3f8527a
15
source=("${pkgname}-${pkgver}.zip::https://github.com/leejet/stable-diffusion.cpp/releases/download/${_upstream_tag}/sd-master-${_commit}-bin-Linux-Ubuntu-24.04-x86_64-vulkan.zip")
16
sha256sums=('e35cc73cf5ba9637d1dc1d717760e7b8428376a4905d57e72ec8c871864f62c7')
17
18
package() {
19
local upstream="$srcdir" executable license_file
20
test -x "$upstream/sd-cli"
21
test -x "$upstream/sd-server"
22
test -f "$upstream/libggml-vulkan.so"
23
test -f "$upstream/stable-diffusion.cpp.txt"
24
test -f "$upstream/ggml.txt"
25
26
install -d "$pkgdir/usr/lib/$pkgname" "$pkgdir/usr/bin"
27
cp -a "$upstream/." "$pkgdir/usr/lib/$pkgname/"
28
rm -f "$pkgdir/usr/lib/$pkgname/${pkgname}-${pkgver}.zip"
29
for license_file in "$pkgdir/usr/lib/$pkgname"/*.txt; do
30
[[ -f "$license_file" ]] || continue
31
install -Dm644 "$license_file" "$pkgdir/usr/share/licenses/$pkgname/${license_file##*/}"
32
rm "$license_file"
33
done
34
for executable in sd-cli sd-server; do
35
ln -s "../lib/$pkgname/$executable" "$pkgdir/usr/bin/$executable"
36
done
37
}
38
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 08:02:16 | Medium | 2 |