thinkwatch-lite-bin

LOW
maintainer sunnysab 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package unpacks an upstream AppImage from GitHub Releases, which is a normal practice for AUR packages when upstream only provides binaries; the build process removes bundled libraries to ensure compatibility and installs files under pacman control, with no evidence of malicious behavior.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package unpacks an upstream AppImage from GitHub Releases, which is a normal practice for AUR packages when upstream only provides binaries; the build process removes bundled libraries to ensure compatibility and installs files under pacman control, with no evidence of malicious behavior.

PKGBUILD

1# Maintainer: sunnysab <i@sunnysab.cn>
2#
3# Upstream ships an AppImage only. This unpacks that AppImage so pacman owns
4# every file and the app cannot replace itself underneath the package.
5pkgname=thinkwatch-lite-bin
6pkgver=2026.10.2
7pkgrel=1
8pkgdesc="A local gateway for Claude Code, Codex and other AI clients"
9arch=('x86_64')
10url="https://github.com/ThinkWatchProject/ThinkWatch-Lite"
11license=('MIT')
12depends=('e2fsprogs' 'expat' 'fontconfig' 'freetype2' 'fribidi' 'harfbuzz'
13 'hicolor-icon-theme' 'libdrm' 'libglvnd' 'libgpg-error' 'libx11'
14 'libxcb' 'mesa' 'wayland' 'zlib')
15# The asset name carries the version, and the aur-action updater rewrites this
16# line from the release: upstream renamed it once already.
17_asset="ThinkWatch-Lite-$pkgver-linux-x86_64.AppImage"
18source=("$_asset::https://github.com/ThinkWatchProject/ThinkWatch-Lite/releases/download/v$pkgver/$_asset"
19 "LICENSE::https://raw.githubusercontent.com/ThinkWatchProject/ThinkWatch-Lite/v$pkgver/LICENSE")
20sha256sums=('2119a66982688aaf66399a2be05d7ef0bd0badf910602b45e74e620ef66115ac'
21 '7252131fc6a9010e307564a50152aeae79c6bde89665b3e4b3f2aca9591749dd')
22
23build() {
24 chmod +x "$_asset"
25 ./"$_asset" --appimage-extract > /dev/null
26 cd squashfs-root
27
28 # The AppImage carries the graphics stack of the distribution it was built
29 # on. WebKitGTK asks Mesa for an EGL display, Mesa loads the bundled
30 # libwayland-client, and on a host with a newer Wayland that call fails with
31 # EGL_BAD_PARAMETER: the web process dies and the window stays blank.
32 # Removing these four makes Mesa and GTK use the host's copies.
33 rm -f usr/lib/libwayland-client.so.0 usr/lib/libwayland-cursor.so.0 \
34 usr/lib/libwayland-egl.so.1 usr/lib/libwayland-server.so.0
35
36 # Extraction does not restore the AppDir's modes; the executable bit is put
37 # back on the files that carry it in the mounted image.
38 find . -type f -exec chmod 644 {} +
39 find . -type d -exec chmod 755 {} +
40 chmod 755 AppRun AppRun.wrapped usr/bin/* "usr/lib/ThinkWatch Lite/twcore" \
41 usr/lib/*-linux-gnu/webkit2gtk-4.1/WebKit*
42}
43
44package() {
45 cd squashfs-root
46
47 install -d "$pkgdir/opt/$pkgname" "$pkgdir/usr/bin" "$pkgdir/usr/share/applications"
48 # The whole AppDir: AppRun.wrapped reads `Exec=` from the .desktop file in the
49 # AppDir root, so that file has to stay next to AppRun.
50 cp -a . "$pkgdir/opt/$pkgname/"
51
52 printf '#!/bin/sh\nexec /opt/%s/AppRun "$@"\n' "$pkgname" > "$pkgdir/usr/bin/${pkgname%-bin}"
53 chmod 755 "$pkgdir/usr/bin/${pkgname%-bin}"
54
55 # The app writes this entry itself when it runs as an AppImage, so that
56 # thinkwatch:// (the sign-in callback) finds it; as a package the entry is
57 # ours instead, under the app's own identifier for notification attribution.
58 cat > "$pkgdir/usr/share/applications/app.thinkwatch.lite.desktop" <<'EOF'
59[Desktop Entry]
60Type=Application
61Name=ThinkWatch Lite
62Comment=Local gateway for Claude Code, Codex and other AI clients
63Exec=/usr/bin/thinkwatch-lite %u
64Icon=app.thinkwatch.lite
65Terminal=false
66Categories=Development;
67MimeType=x-scheme-handler/thinkwatch;
68StartupWMClass=thinkwatch-lite
69EOF
70 chmod 644 "$pkgdir/usr/share/applications/app.thinkwatch.lite.desktop"
71
72 for size in 32 128 256 512; do
73 install -Dm644 "usr/share/icons/hicolor/${size}x${size}/apps/thinkwatch-lite.png" \
74 "$pkgdir/usr/share/icons/hicolor/${size}x${size}/apps/app.thinkwatch.lite.png"
75 done
76
77 install -Dm644 "$srcdir/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
78}
79

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion