ungoogled-chromium-xdg
The package builds Chromium from official source code hosted on Google's own storage domain, which is a standard and trusted source for Chromium; the non-whitelisted host is a known official infrastructure, not a risk for supply-chain tampering.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds Chromium from official source code hosted on Google's own storage domain, which is a standard and trusted source for Chromium; the non-whitelisted host is a known official infrastructure, not a risk for supply-chain tampering.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:91
source=(https://commondatastorage.googleapis.com/chromium-browser-official/chromium-$pkgver-lite.tar.xz
PKGBUILD
1 offending line(s) highlighted# Maintainer: Noah Vogt (noahvogt) <noah@noahvogt.com>
# Maintainer: Seppia <seppia@seppio.fish>
# Maintainer: JustKidding <jk@vin.ovh>
# Based on extra/chromium, with ungoogled-chromium patches
# Maintainer: Evangelos Foutras <evangelos@foutrelis.com>
# Contributor: Pierre Schmitz <pierre@archlinux.de>
# Contributor: Jan "heftig" Steffens <jan.steffens@gmail.com>
# Contributor: Daniel J Griffiths <ghost1227@archlinux.us>
# binary version of this package (-bin): github.com/noahvogt/ungoogled-chromium-xdg-bin-aur
pkgname=ungoogled-chromium-xdg
pkgver=153.0.8010.36
pkgrel=1
_launcher_ver=8
_manual_clone=0
_system_clang=1
_uc_usr=ungoogled-software
_uc_ver=$pkgver-1
pkgdesc="A lightweight approach to removing Google web service dependency - allow disabling omnibox auto completion"
arch=('x86_64')
url="https://github.com/ungoogled-software/ungoogled-chromium"
license=('BSD-3-Clause')
depends=(
'alsa-lib'
'at-spi2-core'
'cairo'
'dbus'
'desktop-file-utils'
'expat'
'glib2'
'glibc'
'gtk3'
'hicolor-icon-theme'
'libcups'
'libffi'
'libgcc'
'libgcrypt'
'libpulse'
'libstdc++'
'libva'
'libx11'
'libxcb'
'libxcomposite'
'libxdamage'
'libxext'
'libxfixes'
'libxkbcommon'
'libxrandr'
'libxss'
'mesa'
'nspr'
'nss'
'pango'
'pciutils'
'systemd'
'systemd-libs'
'ttf-liberation'
'xdg-utils'
'zlib'
)
makedepends=(
'clang'
'compiler-rt'
'git'
'gn'
'go'
'gperf'
'java-runtime-headless'
'lld'
'ninja'
'nodejs'
'opus'
'pipewire'
'python'
'qt6-base'
'rust'
'rust-bindgen'
'typescript'
)
optdepends=('pipewire: WebRTC desktop sharing under Wayland'
'kdialog: support for native dialogs in Plasma'
'gtk4: for --gtk-version=4 (GTK4 IME might work better on Wayland)'
'qt6-base: Qt support'
'org.freedesktop.secrets: password storage backend on GNOME, KDE and Xfce'
'upower: Battery Status API support'
'chromium-extension-web-store: Web Store Functionality')
options=('!lto') # Chromium adds its own flags for ThinLTO
source=(https://commondatastorage.googleapis.com/chromium-browser-official/chromium-$pkgver-lite.tar.xz
"ungoogled-chromium-$_uc_ver.tar.gz::https://github.com/$_uc_usr/ungoogled-chromium/archive/$_uc_ver.tar.gz"
https://github.com/foutrelis/chromium-launcher/archive/v$_launcher_ver/chromium-launcher-$_launcher_ver.tar.gz
chromium-138-nodejs-version-check.patch
chromium-145-fix-SYS_SECCOMP.patch
chromium-147-revert-clang-no-lifetime-dse-flag.patch
chromium-147-rust-1.95-bytemuck.patch
chromium-149-drop-unknown-clang-flag.patch
chromium-149-use-of-undeclared-identifier-ERROR.patch
chromium-150-revert-avx-flag-change.patch
chromium-152-fix-gn-no-public_inputs.patch
chromium-152-unbundle-minizip-undo-unicode.patch
chromium-152-unbundle-opus-devtools.patch
chromium-153-hermetic-python.patch
chromium-153-iamf-tools-unbundled-opus.patch
chromium-153-typescript.patch
chromium-153-crubit.patch
compiler-rt-adjust-paths.patch
increase-fortify-level.patch
enable-widevine-arm64.patch
use-oauth2-client-switches-as-default.patch
glibc-2.42-baud-rate-fix.patch
# ungoogled-chromium-xdg patches
no-omnibox-suggestion-autocomplete.patch)
sha256sums=('645f64566cfbb780747430d53ff3656f03639f89fed9544c1eadd4c17e7b1c82'
'8df8570d440a9117c187f1c466386543381c52bb9044817670df8a741423ca12'
'213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a'
'11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e'
'4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e'
'c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a'
'b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05'
'1b5190fa030850cf30a97dc90e35b31f3097243c88743fbfaedbd64ea80f1327'
'951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4'
'5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60'
'50115642099ac131f40c419cbd12ed72e352538002d4bdc11ab657335891d03b'
'890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9'
'3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3'
'ebf74154266d0b6d6cc957c413f845052c5fcfce7745befb8821595cdf3f7d49'
'2ab9fbe653829ce692f83ee780aad07e8c83a6686e51ab9459ad736cfa2850ee'
'44c86a7c26d726559d5bd06a64f81e6bcced7ab4dc949c899e4fd2c64ff37a16'
'a20e615fa03713e464fc3f2966c84e2130b6d942a4c8b5919ba0bf8320d39ed4'
'ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863'
'd634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342'
'5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928'
'9343afa1a4308a7cfb3317229f5aff7778688debcc03c4a74a85908aa1d0cc3a'
'1c1898f263eaacbc069a8e1a3e732852350350d1dad4cb1a6bba430e3b796cd0'
'ed335a6b4b9c05fff5fbfb530e83bdd165c002f2219d0adbf9773bc3239620e6')
if (( _manual_clone )); then
source[0]=fetch-chromium-release
sha256sums[0]='2e2f36e3cd1ebc4ad57fd310774a5e5e9db77883d5f9374fedeaabd3c103b819'
makedepends+=('python-httplib2' 'python-pyparsing' 'python-six' 'npm' 'rsync')
fi
provides=("chromium=${pkgver}" "chromedriver=${pkgver}")
conflicts=('chromium' 'chromedriver')
# Possible replacements are listed in build/linux/unbundle/replace_gn_files.py
# Keys are the names in the above script; values are the dependencies in Arch
declare -gA _system_libs=(
[brotli]=brotli
[dav1d]=dav1d
#[ffmpeg]=ffmpeg # YouTube playback stopped working in Chromium 120
[flac]=flac
[fontconfig]=fontconfig
[freetype]=freetype2
[harfbuzz]=harfbuzz
[highway]=highway
#[icu]=icu
#[jsoncpp]=jsoncpp # needs libstdc++
#[libaom]=aom
#[libavif]=libavif # needs -DAVIF_ENABLE_EXPERIMENTAL_GAIN_MAP=ON
[libdrm]=libdrm
[libjpeg]=libjpeg-turbo
#[libpng]=libpng # libpng has been replaced by the png rust crate
#[libvpx]=libvpx
[libwebp]=libwebp
[libxml]=libxml2
[libxslt]=libxslt
[openh264]=openh264
[opus]=opus
#[re2]=re2 # needs libstdc++
#[snappy]=snappy # needs libstdc++
#[woff2]=woff2 # needs libstdc++
[zlib]=minizip
[zstd]=zstd
)
_unwanted_bundled_libs=(
$(printf "%s\n" ${!_system_libs[@]} | sed 's/^libjpeg$/&_turbo/')
)
depends+=(${_system_libs[@]})
# Google API keys (see https://www.chromium.org/developers/how-tos/api-keys)
# Note: These are for Arch Linux use ONLY. For your own distribution, please
# get your own set of keys.
#
# Starting with Chromium 89 (2021-03-02) the OAuth2 credentials have been left
# out: https://archlinux.org/news/chromium-losing-sync-support-in-early-march/
prepare() {
if (( _manual_clone )); then
./fetch-chromium-release $pkgver
fi
cd chromium-$pkgver
# Allow building against system libraries in official builds
sed -i 's/OFFICIAL_BUILD/GOOGLE_CHROME_BUILD/' \
tools/generate_shim_headers/generate_shim_headers.py
# https://crbug.com/893950
sed -i -e 's/\<xmlMalloc\>/malloc/' -e 's/\<xmlFree\>/free/' \
-e '1i #include <cstdlib>' \
third_party/blink/renderer/core/xml/*.cc \
third_party/blink/renderer/core/xml/parser/xml_document_parser.cc \
third_party/libxml/chromium/*.cc
# Use the --oauth2-client-id= and --oauth2-client-secret= switches for
# setting GOOGLE_DEFAULT_CLIENT_ID and GOOGLE_DEFAULT_CLIENT_SECRET at
# runtime -- this allows signing into Chromium without baked-in values
patch -Np1 -i ../use-oauth2-client-switches-as-default.patch
# Upstream fixes
# Fixes from Gentoo
patch -Np1 -i ../chromium-138-nodejs-version-check.patch
# Allow libclang_rt.builtins from compiler-rt >= 16 to be used
patch -Np1 -i ../compiler-rt-adjust-paths.patch
# Increase _FORTIFY_SOURCE level to match Arch's default flags
patch -Np1 -i ../increase-fortify-level.patch
# clang 22 lacks -fsanitize-ignore-for-ubsan-feature, which is needed to use
# -fsanitize=array-bounds without triggering UBSan feature detection. Without
# feature detection suppression, V8 compiles in __sanitizer_set_death_callback
# calls that require the UBSan runtime, which is not linked in a trap-mode
# build. Drop the entire sanitize_c_array_bounds cflags block.
# Can be dropped when arch has LLVM 23.
patch -Np1 -i ../chromium-149-drop-unknown-clang-flag.patch
# Causes a build failure with our clang version
patch -Np1 -i ../chromium-147-revert-clang-no-lifetime-dse-flag.patch
# https://crbug.com/456218403
patch -Np1 -i ../chromium-145-fix-SYS_SECCOMP.patch
patch -Np1 -i ../chromium-147-rust-1.95-bytemuck.patch
# enable widevine for arm64
patch -Np1 -i ../enable-widevine-arm64.patch
# https://crbug.com/456677057
patch -Np1 -i ../glibc-2.42-baud-rate-fix.patch
patch -Np1 -i ../chromium-149-use-of-undeclared-identifier-ERROR.patch
# Fix issue about missing AVX functions
# Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837
patch -Np1 -i ../chromium-150-revert-avx-flag-change.patch
# Just the reverted commit 8dab8b761385b7946588232e4e2a8c116f9293c3
patch -Np1 -i "$srcdir/chromium-152-fix-gn-no-public_inputs.patch" -d third_party/devtools-frontend/src
patch -Np1 -i ../chromium-152-unbundle-minizip-undo-unicode.patch
patch -Np1 -i ../chromium-152-unbundle-opus-devtools.patch
# Use system python3 instead of the hermetic cpython3 interpreter
# https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
patch -Np1 -i ../chromium-153-hermetic-python.patch
# third_party/iamf_tools includes vendored Opus via relative "include/opus.h"
# paths that only resolve against a real bundled Opus checkout; fix them up
# for the unbundled system Opus build
patch -Np1 -i ../chromium-153-iamf-tools-unbundled-opus.patch
# Work around TypeScript becoming a build dependency: disable tsgo for the
# WebUI and point devtools at the system tsc binary
# https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
patch -Np1 -i ../chromium-153-typescript.patch
patch -Np1 -i ../chromium-153-crubit.patch
# Custom Patches
# You can now set '1' in the flag #omnibox-ui-max-autocomplete-matches to
# effectively disable autocompletion in the url bar (and therefore the so-
# called 'shoulder surfing').
patch -p1 -i ../no-omnibox-suggestion-autocomplete.patch
if (( !_system_clang )); then
# Use prebuilt rust as system rust cannot be used due to the error:
# error: the option `Z` is only accepted on the nightly compiler
./tools/rust/update_rust.py
# To link to rust libraries we need to compile with prebuilt clang
./tools/clang/scripts/update.py
else
# To fix missing libadler.rlib
sed -i 's/rustc_nightly_capability = use_chromium_rust_toolchain/rustc_nightly_capability = true/' \
build/config/rust.gni
fi
# Ungoogled Chromium changes
_ungoogled_repo="$srcdir/${pkgname%xdg*}$_uc_ver"
_utils="${_ungoogled_repo}/utils"
msg2 'Pruning binaries'
python "$_utils/prune_binaries.py" ./ "$_ungoogled_repo/pruning.list"
msg2 'Applying patches'
python "$_utils/patches.py" apply ./ "$_ungoogled_repo/patches"
msg2 'Applying domain substitution'
python "$_utils/domain_substitution.py" apply -r "$_ungoogled_repo/domain_regex.list" \
-f "$_ungoogled_repo/domain_substitution.list" -c domainsubcache.tar.gz ./
# Link to system tools required by the build
mkdir -p third_party/node/linux/node-linux-x64/bin \
third_party/rust-toolchain/bin \
third_party/jdk/current/bin \
third_party/gperf/cipd/bin \
third_party/dawn/tools/golang/linux-amd64/bin
ln -s /usr/bin/node third_party/node/linux/node-linux-x64/bin/
if (( ! _manual_colne )); then
ln -s /usr/bin/rustc third_party/rust-toolchain/bin/
fi
ln -s /usr/bin/java third_party/jdk/current/bin/
ln -s /usr/bin/gperf third_party/gperf/cipd/bin/
ln -s /usr/bin/go third_party/dawn/tools/golang/linux-amd64/bin/
# Remove bundled libraries for which we will use the system copies; this
# *should* do what the remove_bundled_libraries.py script does, with the
# added benefit of not having to list all the remaining libraries
local _lib
for _lib in ${_unwanted_bundled_libs[@]}; do
find "third_party/$_lib" -type f \
\! -path "third_party/$_lib/chromium/*" \
\! -path "third_party/$_lib/google/*" \
\! -path "third_party/harfbuzz-ng/utils/hb_scoped.h" \
\! -regex '.*\.\(gn\|gni\|isolate\)' \
-delete
done
./build/linux/unbundle/replace_gn_files.py \
--system-libraries "${!_system_libs[@]}"
# Generate missing header
if (( _manual_clone )); then
python3 build/util/lastchange.py -m DAWN_COMMIT_HASH \
-s third_party/dawn --revision gpu/webgpu/DAWN_VERSION \
--header gpu/webgpu/dawn_commit_hash.h
fi
}
build() {
make -C chromium-launcher-$_launcher_ver
cd chromium-$pkgver
if (( _system_clang )); then
export CC=clang
export CXX=clang++
export AR=ar
export NM=nm
else
local _clang_path="$PWD/third_party/llvm-build/Release+Asserts/bin"
export CC=$_clang_path/clang
export CXX=$_clang_path/clang++
export AR=$_clang_path/llvm-ar
export NM=$_clang_path/llvm-nm
fi
local _flags=(
'custom_toolchain="//build/toolchain/linux/unbundle:default"'
'host_toolchain="//build/toolchain/linux/unbundle:default"'
'is_official_build=true' # implies is_cfi=true on x86_64
'symbol_level=0' # sufficient for backtraces on x86(_64)
'treat_warnings_as_errors=false'
'fatal_linker_warnings=false'
'disable_fieldtrial_testing_config=true'
'blink_enable_generated_code_formatting=false'
'ffmpeg_branding="Chrome"'
'proprietary_codecs=true'
'rtc_use_pipewire=true'
'link_pulseaudio=true'
'use_custom_libcxx=true' # https://github.com/llvm/llvm-project/issues/61705
'use_sysroot=false'
'use_system_libffi=true'
'enable_widevine=true'
'use_qt5=false'
'use_qt6=true'
'moc_qt6_path="/usr/lib/qt6"'
'enable_platform_hevc=true'
'enable_hevc_parser_and_hw_decoder=true'
'use_clang_modules=false'
)
if [[ -n ${_system_libs[icu]+set} ]]; then
_flags+=('icu_use_data_file=false')
fi
# Append ungoogled chromium flags to _flags array
_ungoogled_repo="$srcdir/${pkgname%xdg*}$_uc_ver"
readarray -t -O ${#_flags[@]} _flags < "${_ungoogled_repo}/flags.gn"
if (( _system_clang )); then
local _clang_version=$(
clang --version | grep -m1 version | sed 's/.* \([0-9]\+\).*/\1/')
_flags+=(
'clang_base_path="/usr"'
'clang_use_chrome_plugins=false'
"clang_version=\"$_clang_version\""
'chrome_pgo_phase=0' # needs newer clang to read the bundled PGO profile
)
# Allow the use of nightly features with stable Rust compiler
# https://github.com/ungoogled-software/ungoogled-chromium/pull/2696#issuecomment-1918173198
export RUSTC_BOOTSTRAP=1
_flags+=(
'rust_sysroot_absolute="/usr"'
'rust_bindgen_root="/usr"'
"rustc_version=\"$(rustc --version | awk '{ print $2 ;}')\""
)
fi
# Facilitate deterministic builds (taken from build/config/compiler/BUILD.gn)
CFLAGS+=' -Wno-builtin-macro-redefined'
CXXFLAGS+=' -Wno-builtin-macro-redefined'
CPPFLAGS+=' -D__DATE__= -D__TIME__= -D__TIMESTAMP__='
# Do not warn about unknown warning options
CFLAGS+=' -Wno-unknown-warning-option'
CXXFLAGS+=' -Wno-unknown-warning-option'
# Let Chromium set its own symbol level
CFLAGS=${CFLAGS/-g }
CXXFLAGS=${CXXFLAGS/-g }
# https://github.com/ungoogled-software/ungoogled-chromium-archlinux/issues/123
CFLAGS=${CFLAGS/-fexceptions}
CFLAGS=${CFLAGS/-fcf-protection}
CXXFLAGS=${CXXFLAGS/-fexceptions}
CXXFLAGS=${CXXFLAGS/-fcf-protection}
# This appears to cause random segfaults when combined with ThinLTO
# https://bugs.archlinux.org/task/73518
CFLAGS=${CFLAGS/-fstack-clash-protection}
CXXFLAGS=${CXXFLAGS/-fstack-clash-protection}
# https://crbug.com/957519#c122
CXXFLAGS=${CXXFLAGS/-Wp,-D_GLIBCXX_ASSERTIONS}
if [[ $CARCH == aarch64 ]] || [[ $CARCH == riscv64 ]]; then
# On aarch64 and riscv64, certain files (e.g. in libvpx and libyuv) needs to
# be compiled with additional arch features (e.g. dotprod, sve, sme, rvv)
# Having an arch setting in the C(XX)FLAGS overrides those
# and causes compilation failure
CFLAGS="${CFLAGS/-march=*([^ ]) }"
CXXFLAGS="${CXXFLAGS/-march=*([^ ]) }"
fi
gn gen out/Release --args="${_flags[*]}"
ninja -C out/Release chrome chrome_sandbox chromedriver
}
package() {
cd chromium-launcher-$_launcher_ver
make PREFIX=/usr DESTDIR="$pkgdir" install
install -Dvm644 LICENSE \
"$pkgdir/usr/share/licenses/chromium/LICENSE.launcher"
cd ../chromium-$pkgver
install -Dv out/Release/chrome "$pkgdir/usr/lib/chromium/chromium"
install -Dv out/Release/chromedriver "$pkgdir/usr/bin/chromedriver"
install -Dvm4755 out/Release/chrome_sandbox "$pkgdir/usr/lib/chromium/chrome-sandbox"
install -Dvm644 chrome/installer/linux/common/desktop.template \
"$pkgdir/usr/share/applications/chromium.desktop"
install -Dvm644 chrome/app/resources/manpage.1.in \
"$pkgdir/usr/share/man/man1/chromium.1"
sed -i \
-e 's/@@MENUNAME/Chromium/g' \
-e 's/@@PACKAGE/chromium/g' \
-e 's/@@usr_bin_symlink_name/chromium/g' \
-e 's|@@uri_scheme|x-scheme-handler/chromium;|g' \
-e 's/@@extra_desktop_entries//g' \
"$pkgdir/usr/share/applications/chromium.desktop" \
"$pkgdir/usr/share/man/man1/chromium.1"
# Fill in common Chrome/Chromium AppData template with Chromium info
(
tmpl_file=chrome/installer/linux/common/appdata.xml.template
info_file=chrome/installer/linux/common/chromium-browser.info
. $info_file; PACKAGE=chromium
export $(grep -o '^[A-Z_]*' $info_file)
sed -E -e 's/@@([A-Z_]*)/\${\1}/g' -e '/<update_contact>/d' $tmpl_file | envsubst
) \
| install -Dvm644 /dev/stdin "$pkgdir/usr/share/metainfo/chromium.appdata.xml"
local toplevel_files=(
chrome_100_percent.pak
chrome_200_percent.pak
chrome_crashpad_handler
libqt6_shim.so
resources.pak
v8_context_snapshot.bin
# ANGLE
libEGL.so
libGLESv2.so
# SwiftShader ICD
libvk_swiftshader.so
libvulkan.so.1
vk_swiftshader_icd.json
)
if [[ -z ${_system_libs[icu]+set} ]]; then
toplevel_files+=(icudtl.dat)
fi
cp "${toplevel_files[@]/#/out/Release/}" "$pkgdir/usr/lib/chromium/"
install -Dvm644 -t "$pkgdir/usr/lib/chromium/locales" out/Release/locales/*.pak
for size in 24 48 64 128 256; do
install -Dvm644 "chrome/app/theme/chromium/product_logo_$size.png" \
"$pkgdir/usr/share/icons/hicolor/${size}x${size}/apps/chromium.png"
done
for size in 16 32; do
install -Dvm644 "chrome/app/theme/default_100_percent/chromium/product_logo_$size.png" \
"$pkgdir/usr/share/icons/hicolor/${size}x${size}/apps/chromium.png"
done
install -Dvm644 LICENSE "$pkgdir/usr/share/licenses/chromium/LICENSE"
}
# vim:set ts=2 sw=2 et:
Changes since previous scan
--- PKGBUILD @ 2026-09-15 00:25+++ PKGBUILD @ 2026-09-17 00:27@@ -12,7 +12,7 @@ # binary version of this package (-bin): github.com/noahvogt/ungoogled-chromium-xdg-bin-aur pkgname=ungoogled-chromium-xdg-pkgver=152.0.7977.75+pkgver=153.0.8010.36 pkgrel=1 _launcher_ver=8 _manual_clone=0@@ -72,11 +72,13 @@ 'lld' 'ninja' 'nodejs'+ 'opus' 'pipewire' 'python' 'qt6-base'+ 'rust' 'rust-bindgen'- 'rust'+ 'typescript' ) optdepends=('pipewire: WebRTC desktop sharing under Wayland' 'kdialog: support for native dialogs in Plasma'@@ -96,11 +98,13 @@ chromium-149-drop-unknown-clang-flag.patch chromium-149-use-of-undeclared-identifier-ERROR.patch chromium-150-revert-avx-flag-change.patch- chromium-152-crubit.patch- chromium-152-dawn-llvm-22.patch chromium-152-fix-gn-no-public_inputs.patch chromium-152-unbundle-minizip-undo-unicode.patch chromium-152-unbundle-opus-devtools.patch+ chromium-153-hermetic-python.patch+ chromium-153-iamf-tools-unbundled-opus.patch+ chromium-153-typescript.patch+ chromium-153-crubit.patch compiler-rt-adjust-paths.patch increase-fortify-level.patch enable-widevine-arm64.patch@@ -108,21 +112,23 @@ glibc-2.42-baud-rate-fix.patch # ungoogled-chromium-xdg patches no-omnibox-suggestion-autocomplete.patch)-sha256sums=('12379ddd4cdce9c318787c32f438dcf386df59b72ba508eb9f9ece54be44eb66'- '0754581d607ab3806cb5dbb319f28d0bb0cddfe6c64015b59dff7d40c859cddb'+sha256sums=('645f64566cfbb780747430d53ff3656f03639f89fed9544c1eadd4c17e7b1c82'+ '8df8570d440a9117c187f1c466386543381c52bb9044817670df8a741423ca12' '213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a' '11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e' '4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e' 'c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a' 'b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05'- 'e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9'+ '1b5190fa030850cf30a97dc90e35b31f3097243c88743fbfaedbd64ea80f1327' '951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4' '5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60'- '6cf0b76bc5d9c9bb82ecde1fa87ed1f4380b4bbd29ea485261e5f2aada5d71ea'- '5e465d199c1a28d58078af08bcab151561d6423f43c6dba57d4db3f5de534140'- '5c4640a211d02ba8249299842ea2999ccc239d85bfd59a0f7c302483683adc07'+ '50115642099ac131f40c419cbd12ed72e352538002d4bdc11ab657335891d03b' '890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9' '3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3'+ 'ebf74154266d0b6d6cc957c413f845052c5fcfce7745befb8821595cdf3f7d49'+ '2ab9fbe653829ce692f83ee780aad07e8c83a6686e51ab9459ad736cfa2850ee'+ '44c86a7c26d726559d5bd06a64f81e6bcced7ab4dc949c899e4fd2c64ff37a16'+ 'a20e615fa03713e464fc3f2966c84e2130b6d942a4c8b5919ba0bf8320d39ed4' 'ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863' 'd634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342' '5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928'@@ -149,6 +155,7 @@ [fontconfig]=fontconfig [freetype]=freetype2 [harfbuzz]=harfbuzz+ [highway]=highway #[icu]=icu #[jsoncpp]=jsoncpp # needs libstdc++ #[libaom]=aom@@ -241,16 +248,28 @@ # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837 patch -Np1 -i ../chromium-150-revert-avx-flag-change.patch - patch -Np1 -i ../chromium-152-crubit.patch-- patch -Np1 -i ../chromium-152-dawn-llvm-22.patch- # Just the reverted commit 8dab8b761385b7946588232e4e2a8c116f9293c3 patch -Np1 -i "$srcdir/chromium-152-fix-gn-no-public_inputs.patch" -d third_party/devtools-frontend/src patch -Np1 -i ../chromium-152-unbundle-minizip-undo-unicode.patch patch -Np1 -i ../chromium-152-unbundle-opus-devtools.patch++ # Use system python3 instead of the hermetic cpython3 interpreter+ # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946+ patch -Np1 -i ../chromium-153-hermetic-python.patch++ # third_party/iamf_tools includes vendored Opus via relative "include/opus.h"+ # paths that only resolve against a real bundled Opus checkout; fix them up+ # for the unbundled system Opus build+ patch -Np1 -i ../chromium-153-iamf-tools-unbundled-opus.patch++ # Work around TypeScript becoming a build dependency: disable tsgo for the+ # WebUI and point devtools at the system tsc binary+ # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946+ patch -Np1 -i ../chromium-153-typescript.patch++ patch -Np1 -i ../chromium-153-crubit.patch # Custom Patches Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 05:18:46 | Medium | 1 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 03:59:20 | Medium | 1 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 07:57:01 | Medium | 1 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |