veshell

LOW
maintainer PapyElGringo 0 votes scanned 2026-10-07 14:14:59.268871
View on AUR
Why flagged

All sources are either from the official project repo, Google's Flutter infrastructure (storage.googleapis.com), or the project's own GitHub releases with pinned checksums; the only non-standard host is the _input_mirror variable pointing to the project's own packaging releases on GitHub, which is legitimate project infrastructure, and all artifacts have explicit sha256sums.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 75%): All sources are either from the official project repo, Google's Flutter infrastructure (storage.googleapis.com), or the project's own GitHub releases with pinned checksums; the only non-standard host is the _input_mirror variable pointing to the project's own packaging releases on GitHub, which is legitimate project infrastructure, and all artifacts have explicit sha256sums.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:64 "flutter_linux_${_flutter_version}-stable.tar.xz::https://storage.googleapis.com/flutter_infra_release/releases/stable/linux/flutter_linux_3.47.2-stable.tar.xz"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Adrien Peslerbe <adrien@pesler.be>
2# Arch/Manjaro source package for Veshell.
3#
4# Generated from templates/PKGBUILD.in by
5# scripts/render-recipes.py. Do not edit by hand.
6#
7# Builds the Dart shell and the Rust compositor from source, entirely offline.
8# All external Flutter inputs are pinned and checksummed: the official Flutter
9# SDK bundle, the matching engine artifacts, and the meta-flutter embedder
10# engine. `build-veshell.sh` is a copy of scripts/build-veshell.sh.
11#
12# The two generated inputs (Cargo vendor tree, Dart pub cache) are published
13# alongside each release. Regenerate and refresh their checksums with
14# scripts/generate-inputs.sh, then re-render this recipe.
15
16pkgname=veshell
17pkgver=0.1.0
18pkgrel=1
19pkgdesc="An innovative Not-Desktop environment for Linux built with Flutter and Rust"
20arch=('x86_64')
21url="https://github.com/free-explorers/veshell"
22license=('GPL-3.0-or-later')
23depends=(
24 'fontconfig' 'ttf-roboto' 'noto-fonts' 'noto-fonts-cjk'
25 'libglvnd' 'mesa'
26 'libinput' 'seatd' 'systemd-libs' 'libxkbcommon'
27 'libdisplay-info'
28 'pipewire' 'libpulse'
29 'gst-plugins-base' 'gst-plugins-base-libs' 'gst-plugins-good'
30 'dbus' 'upower' 'polkit'
31 'xorg-xwayland' 'xdg-desktop-portal' 'xdg-utils'
32)
33makedepends=(
34 'rust' 'clang' 'cmake' 'ninja' 'pkgconf' 'git'
35 'unzip' 'zstd' 'xz'
36 'gtk3' 'libpulse'
37 'libinput' 'seatd' 'mesa' 'openssl'
38 'pipewire' 'gstreamer' 'gst-plugins-base-libs'
39 'libxkbcommon' 'libdisplay-info' 'wayland' 'systemd-libs'
40 'vulkan-icd-loader'
41)
42optdepends=(
43 'networkmanager: network control panel'
44 'bluez: Bluetooth control panel'
45 'rtkit: real-time audio scheduling'
46 'xdg-desktop-portal-gtk: GTK portal fallback backend'
47)
48provides=('wayland-compositor')
49conflicts=('veshell-git')
50# makepkg's global `lto` option adds -flto to CFLAGS. The libspa-sys build
51# script compiles a C shim into a static archive; LTO objects there are not
52# resolved by rustc's final (non-LTO) link. Disable LTO for this package.
53options=('!lto')
54
55# --- pinned inputs ----------------------------------------------------------
56_veshell_commit=e954bb7ebcdfab7892249005c64ff7ba740930d3
57_flutter_version=3.47.2
58_flutter_engine_revision=a804b261645ef8c13eb3d5c44a5c2fb0340c5539
59_input_mirror="${VESHELL_INPUT_MIRROR:-https://github.com/free-explorers/veshell-packaging/releases/download/packaging-inputs-v0.1.0}"
60
61source=(
62 "veshell::git+https://github.com/free-explorers/veshell.git#commit=$_veshell_commit"
63 "build-veshell.sh"
64 "flutter_linux_${_flutter_version}-stable.tar.xz::https://storage.googleapis.com/flutter_infra_release/releases/stable/linux/flutter_linux_3.47.2-stable.tar.xz"
65 "flutter_patched_sdk.zip::https://storage.googleapis.com/flutter_infra_release/flutter/a804b261645ef8c13eb3d5c44a5c2fb0340c5539/flutter_patched_sdk.zip"
66 "flutter_patched_sdk_product.zip::https://storage.googleapis.com/flutter_infra_release/flutter/a804b261645ef8c13eb3d5c44a5c2fb0340c5539/flutter_patched_sdk_product.zip"
67 "linux-x64_artifacts.zip::https://storage.googleapis.com/flutter_infra_release/flutter/a804b261645ef8c13eb3d5c44a5c2fb0340c5539/linux-x64/artifacts.zip"
68 "linux-x64-debug_flutter-gtk.zip::https://storage.googleapis.com/flutter_infra_release/flutter/a804b261645ef8c13eb3d5c44a5c2fb0340c5539/linux-x64-debug/linux-x64-flutter-gtk.zip"
69 "linux-x64-profile_flutter-gtk.zip::https://storage.googleapis.com/flutter_infra_release/flutter/a804b261645ef8c13eb3d5c44a5c2fb0340c5539/linux-x64-profile/linux-x64-flutter-gtk.zip"
70 "linux-x64-release_flutter-gtk.zip::https://storage.googleapis.com/flutter_infra_release/flutter/a804b261645ef8c13eb3d5c44a5c2fb0340c5539/linux-x64-release/linux-x64-flutter-gtk.zip"
71 "linux-engine-sdk-release-x86_64-${_flutter_engine_revision}.tar.gz::https://github.com/free-explorers/flutter-engine/releases/download/linux-engine-sdk-release-x86_64-a804b261645ef8c13eb3d5c44a5c2fb0340c5539/linux-engine-sdk-release-x86_64-a804b261645ef8c13eb3d5c44a5c2fb0340c5539.tar.gz"
72 "veshell-cargo-vendor-0.1.0.tar.zst::$_input_mirror/veshell-cargo-vendor-0.1.0.tar.zst"
73 "veshell-pubcache-0.1.0.tar.zst::$_input_mirror/veshell-pubcache-0.1.0.tar.zst"
74)
75sha256sums=(
76 'SKIP' # pinned git commit
77 '5c1b5bd5fe092615e36a9a3e958d4182c2573f2d0d06ace68f9a6ceb45cd9409' # build-veshell.sh
78 '447878859d01ca9bfdb99a85f245af07ed8a15fedcd9d189c4749e8e92d1f185' # Flutter SDK
79 '5f7d44ecaa2f3d219b9fdf2a1c3977e83545f6f8797fad604f564c1b4154ec8d' # patched_sdk
80 '902bc3b27a1bd3f13b756af2660891dd996eb33ab9bc3e4b89c0c9cfdf49e2aa' # patched_sdk_product
81 '625c7f98c62b9d495638bc71774bf94ad8cae77b070b5f34797ea83b396ebc1c' # linux-x64 artifacts
82 'e324b676106db415bec41d211caeb7a5137d061704f7af83264f382b4e2ff354' # linux-x64 debug gtk
83 '0a507e7c6f49c8905efc809808e1a2ac21bcf2c732b82c10e74f8f1e6d1828ea' # linux-x64 profile gtk
84 '3b357f3df3549c69535d92e8e300a66e1057876dc8fed45a8aae7cf7681b7ec4' # linux-x64 release gtk
85 '539254d41100c2dc338920dae968dc2cf0b7c35e5f00764ab5d24ebc37712f87' # embedder engine
86 'a99abcb0d71d55620df66fe6a81b4543273ca6143311d6c145a204d2241af21f' # cargo vendor
87 '90b0a95878c6735221301b38f363b8e243c679da11aa439286a302ee2c85e264' # pub cache
88)
89
90# The helper extracts every archive itself (into deterministic locations);
91# let makepkg keep the raw sources untouched.
92noextract=(
93 "flutter_linux_${_flutter_version}-stable.tar.xz"
94 "flutter_patched_sdk.zip"
95 "flutter_patched_sdk_product.zip"
96 "linux-x64_artifacts.zip"
97 "linux-x64-debug_flutter-gtk.zip"
98 "linux-x64-profile_flutter-gtk.zip"
99 "linux-x64-release_flutter-gtk.zip"
100 "linux-engine-sdk-release-x86_64-${_flutter_engine_revision}.tar.gz"
101 "veshell-cargo-vendor-0.1.0.tar.zst"
102 "veshell-pubcache-0.1.0.tar.zst"
103)
104
105prepare() {
106 cd veshell
107 mkdir -p "$srcdir/flutter-sdk" "$srcdir/cargo-vendor" "$srcdir/pubcache"
108 tar -xJf "$srcdir/flutter_linux_${_flutter_version}-stable.tar.xz" \
109 -C "$srcdir/flutter-sdk" --strip-components=1
110 tar -xf "$srcdir/veshell-cargo-vendor-0.1.0.tar.zst" -C "$srcdir/cargo-vendor"
111 tar -xf "$srcdir/veshell-pubcache-0.1.0.tar.zst" -C "$srcdir/pubcache"
112}
113
114build() {
115 cd veshell
116 VESHELL_SRC="$PWD" \
117 FLUTTER_SDK_DIR="$srcdir/flutter-sdk" \
118 FLUTTER_ARTIFACT_DIR="$srcdir" \
119 ENGINE_TARBALL="$srcdir/linux-engine-sdk-release-x86_64-${_flutter_engine_revision}.tar.gz" \
120 CARGO_VENDOR_DIR="$srcdir/cargo-vendor" \
121 PUB_CACHE_DIR="$srcdir/pubcache" \
122 PREFIX=/usr \
123 POLKIT_HELPER_PATH=/usr/lib/polkit-1/polkit-agent-helper-1 \
124 JOBS="$(nproc)" \
125 bash "$srcdir/build-veshell.sh" build
126}
127
128package() {
129 cd veshell
130 VESHELL_SRC="$PWD" \
131 PREFIX=/usr \
132 DESTDIR="$pkgdir" \
133 bash "$srcdir/build-veshell.sh" install
134 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
135}
136

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 14:14:59 Low 3
2026-10-07 14:05:47 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion