vega-nostr-git
The `npx tauri build` command runs a build tool from the project's own source repository, which is a normal part of building a Tauri application; the Tauri CLI is pulled from npm as a dev dependency but is not executing untrusted remote code in a malicious context.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The `npx tauri build` command runs a build tool from the project's own source repository, which is a normal part of building a Tauri application; the Tauri CLI is pulled from npm as a dev dependency but is not executing untrusted remote code in a malicious context.
1 higher static finding superseded - not the current verdict (shown for transparency)
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:56
npx tauri build --no-bundle -- --locked
PKGBUILD
1 offending line(s) highlighted# Maintainer: hoornet <hoornet@users.noreply.github.com>
pkgname=vega-nostr-git
pkgver=0.15.7
pkgrel=1
pkgdesc="Cross-platform Nostr desktop client with Lightning integration"
arch=('x86_64')
url="https://github.com/hoornet/vega"
license=('MIT')
depends=(
'webkit2gtk-4.1'
'gtk3'
'libayatana-appindicator'
'openssl'
'gst-plugins-base'
'gst-plugins-good'
'gst-libav'
)
makedepends=(
'rust'
'nodejs'
'npm'
'git'
)
optdepends=(
'gnome-keyring: persistent key storage (any Secret Service provider works)'
'kwallet: Secret Service provider on KDE'
)
provides=('vega-nostr')
conflicts=('vega-nostr')
options=('!debug')
source=("$pkgname::git+https://github.com/hoornet/vega.git")
sha256sums=('SKIP')
pkgver() {
cd "$pkgname"
git describe --tags --long 2>/dev/null | sed 's/^v//;s/-/.r/;s/-/./' || echo "$pkgver"
}
build() {
cd "$pkgname"
# Reset makepkg flags — they interfere with Rust cc crate
# compiling bundled SQLite and Ring assembly
unset CFLAGS CXXFLAGS LDFLAGS
# `npm ci --ignore-scripts`, never `npm install` — this mirrors
# .github/workflows/release.yml. `install` re-resolves inside the caret
# ranges, so a compromised patch release could reach a user's build
# without ever appearing in the reviewed lockfile, and postinstall
# scripts run as the building user. This package builds on the user's
# own machine, so that gap is theirs, not CI's.
npm ci --ignore-scripts
# `-- --locked` forwards to cargo (the Tauri CLI passes trailing args
# through). Cargo's equivalent of `npm ci`: refuse to re-resolve, fail
# instead of silently building a lockfile nobody reviewed.
npx tauri build --no-bundle -- --locked
}
package() {
cd "$pkgname"
install -Dm755 "src-tauri/target/release/vega" \
"$pkgdir/usr/bin/vega"
# Strip build paths from binary (fixes $srcdir reference warning)
strip --strip-unneeded "$pkgdir/usr/bin/vega"
# Icons
install -Dm644 "src-tauri/icons/32x32.png" \
"$pkgdir/usr/share/icons/hicolor/32x32/apps/vega.png"
install -Dm644 "src-tauri/icons/128x128.png" \
"$pkgdir/usr/share/icons/hicolor/128x128/apps/vega.png"
install -Dm644 "src-tauri/icons/128x128@2x.png" \
"$pkgdir/usr/share/icons/hicolor/256x256/apps/vega.png"
# Desktop entry
install -Dm644 /dev/stdin \
"$pkgdir/usr/share/applications/vega.desktop" << 'EOF'
[Desktop Entry]
Name=Vega
Comment=Nostr desktop client
Exec=env WEBKIT_DISABLE_DMABUF_RENDERER=1 /usr/bin/vega
Icon=vega
Type=Application
Categories=Network;InstantMessaging;
StartupNotify=true
EOF
install -Dm644 "LICENSE" \
"$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
Changes since previous scan
--- PKGBUILD @ 2026-09-13 00:19+++ PKGBUILD @ 2026-09-17 00:27@@ -1,6 +1,6 @@ # Maintainer: hoornet <hoornet@users.noreply.github.com> pkgname=vega-nostr-git-pkgver=0.15.6+pkgver=0.15.7 pkgrel=1 pkgdesc="Cross-platform Nostr desktop client with Lightning integration" arch=('x86_64')@@ -41,8 +41,19 @@ # Reset makepkg flags — they interfere with Rust cc crate # compiling bundled SQLite and Ring assembly unset CFLAGS CXXFLAGS LDFLAGS- npm install- npx tauri build --no-bundle++ # `npm ci --ignore-scripts`, never `npm install` — this mirrors+ # .github/workflows/release.yml. `install` re-resolves inside the caret+ # ranges, so a compromised patch release could reach a user's build+ # without ever appearing in the reviewed lockfile, and postinstall+ # scripts run as the building user. This package builds on the user's+ # own machine, so that gap is theirs, not CI's.+ npm ci --ignore-scripts++ # `-- --locked` forwards to cargo (the Tauri CLI passes trailing args+ # through). Cargo's equivalent of `npm ci`: refuse to re-resolve, fail+ # instead of silently building a lockfile nobody reviewed.+ npx tauri build --no-bundle -- --locked } package() {Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 13:14:45 | Medium | 1 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 21:49:23 | Medium | 1 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |