thorium-browser-sse4-bin

LOW
maintainer RubenKelevra 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package downloads a prebuilt .deb binary from the project's official GitHub release page, which is a normal practice for AUR packages; the source is verifiable and matches the project, posing no immediate risk despite the static rule flag for few votes and recent upload.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads a prebuilt .deb binary from the project's official GitHub release page, which is a normal practice for AUR packages; the source is verifiable and matches the project, posing no immediate risk despite the static rule flag for few votes and recent upload.

PKGBUILD

1# Maintainer: @RubenKelevra <rubenkelevra@gmail.com>
2# Contributor: xiota <aur@mentalfossa.com>
3# Contributor: JPratama7 <josepratama080@gmail.com>
4# Contributor: Dominik Adrian Grzywak <starterx4 at gmail dot com>
5
6_pkgname='thorium-browser'
7pkgname="${_pkgname}-sse4-bin"
8pkgbase="${pkgname}"
9pkgver=138.0.7204.303
10pkgrel=1
11pkgdesc='SSE4.1 build of the Chromium fork focused on high performance and security'
12url='https://github.com/Alex313031/thorium'
13license=(
14 'BSD-3-Clause'
15 'LicenseRef-Google-Widevine-CDM'
16)
17arch=('x86_64')
18makedepends=('libarchive')
19depends=(
20 'alsa-lib'
21 'at-spi2-core'
22 'cairo'
23 'dbus'
24 'expat'
25 'glib2'
26 'gtk3'
27 'hicolor-icon-theme'
28 'libcups'
29 'libgcc'
30 'libnotify'
31 'libx11'
32 'libxcb'
33 'libxcomposite'
34 'libxdamage'
35 'libxext'
36 'libxfixes'
37 'libxkbcommon'
38 'libxrandr'
39 'mesa'
40 'nspr'
41 'nss'
42 'pango'
43 'systemd-libs'
44 'ttf-liberation'
45 'xdg-utils'
46)
47optdepends=(
48 'gtk4: GTK4 UI support'
49 'kdialog: native dialogs on Plasma'
50 'libsecret: password storage client integration'
51 'org.freedesktop.secrets: Secret Service backend for password storage'
52 'pipewire: WebRTC desktop sharing under Wayland'
53 'qt5-base: Qt5 UI support'
54 'qt6-base: Qt6 UI support'
55 'upower: Battery Status API support'
56)
57provides=("${_pkgname}=${pkgver}")
58conflicts=(
59 "${_pkgname}"
60 'thorium-browser-avx-bin'
61 'thorium-browser-sse3-bin'
62)
63options=(
64 '!emptydirs'
65 '!strip'
66 '!debug'
67)
68
69_dl_url="${url}/releases/download/M${pkgver}"
70_dl_filename_x86_64="${_pkgname}_${pkgver}_SSE4.deb"
71_license_filename="${_pkgname}-${pkgver}-LICENSE.md"
72_data_archive='data.tar.xz'
73noextract=("${_dl_filename_x86_64}")
74
75source=(
76 "${_pkgname}.sh"
77 'thorium-cpu-check.sh'
78 'thorium-shell.sh'
79 "${_license_filename}::${url}/raw/M${pkgver}/LICENSE.md"
80)
81source_x86_64=("${_dl_url}/${_dl_filename_x86_64}")
82b2sums=(
83 '038ce007f34bc9c519bcc1918ca472cf6596a1dade80b9b150021762a51cf28bc331bb82299110023593f569b9cf285c9ed60d695cfd2abf82d0bf9073ceeee5'
84 '7a9535fa73f8fcfc50dfe1de885c7ea92d104720187d42012fa95bd671e39ec6cb599295e13019712a115b1139d2bedf9969cc7d7472bcf4295380aed91f2f44'
85 '867bc169f526a530a79d1eef5cc463d1c386d380bb574228a46492c9c85fc5dcdaa8768e08282dbe5ed660458613b67da8e3f822a3c9d93866e2252f3332b672'
86 '28458cd9c4ad393fa16d5b0d7bd058643039a5b02769cb10ca7fec2d92929ce4814fd2a6bc594cbb9d5878495f31d3e5f9f44a69c35ab34a7cd21d8d30dca840'
87)
88sha256sums_x86_64=('34cbc8d3a7982bc461e20cb046d819631fd8aff9b68db6c0b10bfe42df5b025b')
89
90prepare() {
91 CARCH="${CARCH}" bash "${srcdir}/thorium-cpu-check.sh" build
92}
93
94package() {
95 printf ' -> Extracting the archive...\n'
96 rm -f -- "${srcdir}/${_data_archive}"
97 bsdtar -C "${srcdir}" -xf "${srcdir}/${_dl_filename_x86_64}" "${_data_archive}"
98 bsdtar -C "${pkgdir}/" -xJf "${srcdir}/${_data_archive}"
99 rm -f -- "${srcdir}/${_data_archive}"
100
101 printf ' -> Moving files in place...\n'
102 mv -- "${pkgdir}/opt/chromium.org/thorium" "${pkgdir}/opt/${_pkgname}"
103 unlink -- "${pkgdir}/usr/bin/thorium-browser"
104 unlink -- "${pkgdir}/usr/bin/pak"
105
106 # thorium-browser
107 install -Dm755 -- "${srcdir}/${_pkgname}.sh" "${pkgdir}/usr/bin/${_pkgname}"
108 install -Dm755 -- "${srcdir}/thorium-cpu-check.sh" \
109 "${pkgdir}/usr/lib/${_pkgname}/check-cpu-support"
110 chmod 4755 -- "${pkgdir}/opt/${_pkgname}/chrome-sandbox"
111
112 local widevine_dir="${pkgdir}/opt/${_pkgname}/WidevineCdm"
113 if [[ ! -f ${widevine_dir}/_platform_specific/linux_x64/libwidevinecdm.so || ! -f ${widevine_dir}/LICENSE ]]; then
114 printf 'Missing bundled x86_64 Widevine CDM or license\n' >&2
115 return 1
116 fi
117 install -Dm644 -- "${widevine_dir}/LICENSE" \
118 "${pkgdir}/usr/share/licenses/${pkgname}/Widevine-LICENSE"
119
120 # Fix upstream paths after moving Thorium out of /opt/chromium.org.
121 if [[ -f ${pkgdir}/opt/${_pkgname}/default-app-block ]]; then
122 sed -E \
123 -e "s@/opt/chromium.org/thorium/@/opt/${_pkgname}/@g" \
124 -i -- "${pkgdir}/opt/${_pkgname}/default-app-block"
125 fi
126
127 # Bring upstream AppStream metadata up to the current schema and path.
128 local metainfo_source="${pkgdir}/usr/share/appdata/thorium-browser.appdata.xml"
129 local metainfo_file="${pkgdir}/usr/share/metainfo/org.chromium.Thorium.metainfo.xml"
130 if [[ ! -f ${metainfo_source} ]]; then
131 printf 'Missing Thorium AppStream metadata: %s\n' "${metainfo_source}" >&2
132 return 1
133 fi
134 install -Dm644 -- "${metainfo_source}" "${metainfo_file}"
135 rm -f -- "${metainfo_source}"
136 rmdir --ignore-fail-on-non-empty -- "${pkgdir}/usr/share/appdata"
137 sed -E \
138 -e 's@<id>thorium-browser[.]desktop</id>@<id>org.chromium.Thorium</id>@' \
139 -e '/<translation\/>/d' \
140 -e 's@<developer_name>([^<]+)</developer_name>@<developer id="io.github.alex313031"><name>\1</name></developer>@' \
141 -i -- "${metainfo_file}"
142 if ! grep -q '<launchable type="desktop-id">' "${metainfo_file}"; then
143 sed -i '/<url type="bugtracker">/i\ <launchable type="desktop-id">thorium-browser.desktop</launchable>' \
144 "${metainfo_file}"
145 fi
146 if ! grep -q '<content_rating type="oars-1.1"' "${metainfo_file}"; then
147 sed -i '/<url type="bugtracker">/i\ <content_rating type="oars-1.1"/>' \
148 "${metainfo_file}"
149 fi
150
151 # thorium-shell
152 install -Dm755 -- "${srcdir}/thorium-shell.sh" "${pkgdir}/usr/bin/thorium-shell"
153 sed -E \
154 -e 's@^Icon=.*@Icon=thorium-shell@' \
155 -i -- "${pkgdir}/usr/share/applications/thorium-shell.desktop"
156
157 # thorium-browser.xml
158 sed -E \
159 -e "s@/opt/chromium.org/thorium/@/opt/${_pkgname}/@" \
160 -i -- "${pkgdir}/usr/share/gnome-control-center/default-apps/thorium-browser.xml"
161
162 # Icons
163 install -Dm644 -- "${pkgdir}/opt/${_pkgname}/product_logo_256.png" \
164 "${pkgdir}/usr/share/icons/hicolor/256x256/apps/${_pkgname}.png"
165 install -Dm644 -- "${pkgdir}/opt/${_pkgname}/thorium_shell.png" \
166 "${pkgdir}/usr/share/icons/hicolor/256x256/apps/thorium-shell.png"
167
168 # Clean up upstream Debian packaging files.
169 rm -r -- \
170 "${pkgdir}/opt/chromium.org" \
171 "${pkgdir}/etc/cron.daily/" \
172 "${pkgdir}/usr/share/doc/" \
173 "${pkgdir}/opt/${_pkgname}/cron/" \
174 "${pkgdir}/opt/${_pkgname}"/product_logo_*.{png,xpm} \
175 "${pkgdir}/usr/share/menu/"
176
177 install -Dm644 -- "${srcdir}/${_license_filename}" \
178 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.md"
179}
180

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion