upm-git

LOW
maintainer cyyynthia 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package builds from the project's own git repository, uses standard build steps, and installs JavaScript source files; the only concerns are a SKIP'd checksum and low votes/new upload, but no remote code execution or malicious behavior is present.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from the project's own git repository, uses standard build steps, and installs JavaScript source files; the only concerns are a SKIP'd checksum and low votes/new upload, but no remote code execution or malicious behavior is present.

PKGBUILD

1# Maintainer: Cynthia Rey <cynthia+aur@cynthia.dev>
2# SPDX-FileCopyrightText: Arch Linux contributors
3# SPDX-License-Identifier: 0BSD
4
5_pkgname=upm
6pkgname=upm-git
7pkgver=1.4.0.r0.g2c98bb4
8pkgrel=1
9pkgdesc='A fast, tiny package manager for the npm registry, written in TypeScript.'
10url='https://github.com/unjs/upm'
11arch=('any')
12depends=(
13 'nodejs>=22.3'
14)
15makedepends=(
16 'git'
17)
18conflicts=(upm upm-bin)
19provides=(upm upm-bin)
20license=('MIT')
21
22source=("git+https://github.com/unjs/upm.git")
23b2sums=('SKIP')
24
25prepare() {
26 cd "$srcdir/$_pkgname"
27 node upm install
28}
29
30build() {
31 cd "$srcdir/$_pkgname"
32 node upm build
33}
34
35package() {
36 local moddir=/usr/lib/node_modules/$_pkgname
37
38 install -dm755 "$pkgdir/usr/bin"
39 ln -s "$moddir/dist/$_pkgname.mjs" "$pkgdir/usr/bin/$_pkgname"
40 ln -s "$moddir/dist/upx.mjs" "$pkgdir/usr/bin/upx"
41
42 install -dm755 "$pkgdir/$moddir"
43 cp -r "$srcdir/$_pkgname/package.json" "$srcdir/$_pkgname/dist" "$pkgdir/$moddir"
44
45 install -Dm644 "$srcdir/$_pkgname/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
46}
47
48pkgver() {
49 cd "$_pkgname"
50 git describe --long --tags | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
51}
52

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion