synkromium-git
The npx command is used to run electron-builder locally after npm ci and npm build, which are standard build steps for an Electron app; the package is built from its own source in the git repository, so this is a normal part of the build process, not execution of a remote package.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The npx command is used to run electron-builder locally after npm ci and npm build, which are standard build steps for an Electron app; the package is built from its own source in the git repository, so this is a normal part of the build process, not execution of a remote package.
1 higher static finding superseded - not the current verdict (shown for transparency)
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:34
npx electron-builder --linux dir -p never
PKGBUILD
1 offending line(s) highlighted# Maintainer: Tokit Auhid <tokitauhidmim12@gmail.com>
pkgname=synkromium-git
pkgver=0.1.6
pkgrel=1
pkgdesc="Keep your Chromium browser settings and extensions in sync across all your devices, privately and automatically."
arch=('x86_64')
url="https://github.com/tokitauhid/Synkromium"
license=('MIT')
depends=('nss' 'libxss' 'libsecret' 'gtk3' 'alsa-lib')
makedepends=('git' 'npm' 'nodejs')
provides=('synkromium')
conflicts=('synkromium' 'synkromium-bin')
source=("git+https://github.com/tokitauhid/Synkromium.git"
"synkromium.desktop")
sha256sums=('SKIP'
'SKIP')
pkgver() {
cd "Synkromium"
# Attempt to use git tags, fallback to rev-list if no tags exist
git describe --long --tags 2>/dev/null | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
}
prepare() {
cd "Synkromium"
npm ci
}
build() {
cd "Synkromium"
npm run build
npx electron-builder --linux dir -p never
}
package() {
cd "Synkromium"
install -d "$pkgdir/opt/Synkromium"
cp -r release/linux-unpacked/* "$pkgdir/opt/Synkromium/"
chmod -R u-s,g-s,o-w,a+rX "$pkgdir"
install -d "$pkgdir/usr/bin"
ln -sf "/opt/Synkromium/synkromium" "$pkgdir/usr/bin/synkromium"
install -Dm644 "../synkromium.desktop" "$pkgdir/usr/share/applications/synkromium.desktop"
install -Dm644 "build/icons/icon.png" "$pkgdir/usr/share/pixmaps/synkromium.png"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |