usb-tree-app

LOW
maintainer Ozum 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The go install command fetches wails build tool from a public Go module, which is a common and legitimate build step for Go projects; it does not execute untrusted external code or install user-facing software via unverified sources.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The go install command fetches wails build tool from a public Go module, which is a common and legitimate build step for Go projects; it does not execute untrusted external code or install user-facing software via unverified sources.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium External install via pipx/uv/poetry/cargo/go/gem alt_pkg_manager_install

A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:25 go install github.com/wailsapp/wails/v2/cmd/wails@latest

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Alastair Ozmond <alastair.ozmond@gmail.com>
2pkgname=usb-tree-app
3pkgver=0.0.6
4pkgrel=1
5pkgdesc="USB device tree viewer with detailed information and monitor"
6arch=('any')
7url="https://github.com/AOzmond/usb-tree"
8license=('GPL-2.0-or-later')
9depends=('gtk3' 'webkit2gtk-4.1' 'libusb')
10makedepends=('go' 'bun-bin' 'git')
11provides=('usb-tree')
12conflicts=('usb-tree' 'usb-tree-app-bin')
13source=("${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/${pkgver}.tar.gz")
14sha256sums=('c1f1653aa691f99abd7a8987daf3603b09c5fcb40a4b309281e6b25c8c17cc08')
15
16build() {
17 cd "${srcdir}/usb-tree-${pkgver}"
18
19 # Install frontend dependencies
20 cd app/frontend
21 bun install
22
23 # Build the application with wails
24 cd ../
25 go install github.com/wailsapp/wails/v2/cmd/wails@latest
26 $(go env GOPATH)/bin/wails build -clean
27}
28
29package() {
30 cd "${srcdir}/usb-tree-${pkgver}"
31
32 # Install binary
33 install -Dm755 "app/build/bin/usb-tree" "${pkgdir}/usr/bin/usb-tree"
34
35 # Install desktop file
36 install -Dm644 "app/build/linux/usb-tree.desktop" "${pkgdir}/usr/share/applications/usb-tree.desktop"
37
38 # Install icon
39 install -Dm644 "app/build/linux/usb-tree.png" "${pkgdir}/usr/share/pixmaps/usb-tree.png"
40
41 # Also install icon in hicolor theme (standard location)
42 install -Dm644 "app/build/linux/usb-tree.png" "${pkgdir}/usr/share/icons/hicolor/256x256/apps/usb-tree.png"
43
44 # Install license
45 install -Dm644 "LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
46}
47

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion