visty-git

maintainer zxp19821005 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The PKGBUILD builds an Electron video player from its official upstream GitHub source. The yarn install pulls npm dependencies as part of a standard build process — this is normal for Electron/Node.js AUR packages and is not meaningfully different from any other npm-based build. The CN mirror logic conditionally redirects to npmmirror.com (a well-known Chinese npm mirror), which is a common pattern in AUR packages targeting Chinese users. The source is a git clone from the official upstream repo with a versioned shell script launcher. No pre-built binaries are downloaded from unofficial hosts; the package builds from source using the system electron. The 'yarn add @electron-forge/plugin-local-electron' is a standard build tool for packaging with a local electron binary. The cheaper model's concern about yarn install is a false positive for this class of package — it applies equally to virtually every Node.js AUR package. The only real concern is the SKIP checksum on the git source (standard for VCS sources) and the dynamic npm dependency resolution, which is a low-severity sloppy practice but not a targeted supply-chain attack.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The PKGBUILD builds an Electron video player from its official upstream GitHub source. The yarn install pulls npm dependencies as part of a standard build process — this is normal for Electron/Node.js AUR packages and is not meaningfully different from any other npm-based build. The CN mirror logic conditionally redirects to npmmirror.com (a well-known Chinese npm mirror), which is a common pattern in AUR packages targeting Chinese users. The source is a git clone from the official upstream repo with a versioned shell script launcher. No pre-built binaries are downloaded from unofficial hosts; the package builds from source using the system electron. The 'yarn add @electron-forge/plugin-local-electron' is a standard build tool for packaging with a local electron binary. The cheaper model's concern about yarn install is a false positive for this class of package — it applies equally to virtually every Node.js AUR package. The only real concern is the SKIP checksum on the git source (standard for VCS sources) and the dynamic npm dependency resolution, which is a low-severity sloppy practice but not a targeted supply-chain attack.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:84 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=visty-git
3_pkgname=Visty
4pkgver=0.0.5.de.r0.g5e7fc1b
5_electronversion=38
6_nodeversion=22
7pkgrel=1
8pkgdesc="Simple Video Player based on Electron.(Use system-wide electron)"
9arch=('any')
10url="https://github.com/fiahfy/visty"
11license=('MIT')
12provides=("${pkgname%-git}=${pkgver%.r*}")
13conflicts=("${pkgname%-git}")
14depends=(
15 "electron${_electronversion}"
16)
17makedepends=(
18 'npm'
19 'nvm'
20 'git'
21 'curl'
22 'gendesk'
23 'yarn'
24)
25source=(
26 "${pkgname//-/.}::git+${url}.git"
27 "${pkgname%-git}.sh"
28)
29sha256sums=('SKIP'
30 '31ad33b633744f5361abd964be306cea53ae1050e760c787115f7eca60045ae6')
31pkgver() {
32 cd "${srcdir}/${pkgname//-/.}"
33 set -o pipefail
34 git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
35 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
36}
37_ensure_local_nvm() {
38 local NVM_DIR="${srcdir}/.nvm"
39 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
40 nvm install "${_nodeversion}"
41 nvm use "${_nodeversion}"
42}
43_get_electron_version() {
44 _elec_ver="$(grep -m 1 '"electron":' "${srcdir}/${pkgname//-/.}/package.json" | cut -d'"' -f4 | tr -d '^' | cut -d. -f1)"
45 echo -e "The electron version is: \033[1;31m${_elec_ver}\033[0m"
46}
47prepare() {
48 cd "${srcdir}/${pkgname//-/.}"
49 _get_electron_version
50 sed -i -e "
51 s/@electronversion@/${_electronversion}/g
52 s/@appname@/${pkgname%-git}/g
53 s/@runname@/app.asar/g
54 s/@cfgdirname@/${_pkgname}/g
55 s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
56 " "${srcdir}/${pkgname%-git}.sh"
57 gendesk -q -f -n \
58 --pkgname="${pkgname%-git}" \
59 --pkgdesc="${pkgdesc}" \
60 --categories="AudioVideo" \
61 --name="${_pkgname}" \
62 --exec="${pkgname%-git} %U"
63 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
64 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
65 HOME="${srcdir}/.electron-gyp"
66 mkdir -p "${srcdir}/.electron-gyp"
67 touch "${srcdir}/.electron-gyp/.yarnrc"
68 if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
69 {
70 echo 'npmRegistryServer: "https://registry.npmmirror.com"'
71 echo "cacheFolder: "${srcdir}"/.yarn/cache"
72 echo "globalFolder: "${srcdir}"/.yarn/global"
73 } >> .yarnrc.yml
74 export npm_config_electron_mirror=https://registry.npmmirror.com/-/binary/electron/
75 export npm_config_electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/
76 fi
77 _ensure_local_nvm
78 #find src -type f -exec sed -i "s/process.resourcesPath/\'\/usr\/lib\/${pkgname%-git}\'/g" {} +
79 sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
80 _yarnver=`grep "yarn@" package.json | awk '{print $2}' | sed "s/\"//g;s/yarn@//g;s/,//g"`
81 corepack enable yarn
82 echo y | yarn version "${_yarnver}"
83 NODE_ENV=development yarn install
84 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
85}
86build() {
87 cd "${srcdir}/${pkgname//-/.}"
88 _ensure_local_nvm
89 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
90 local electronDist="/usr/lib/electron${_electronversion}"
91 sed -i "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
92 {\\
93 name: \"@electron-forge/plugin-local-electron\",\\
94 config: {\\
95 electronPath: \'${electronDist}\',\\
96 },\\
97 }," forge.config.*
98 NODE_ENV=production yarn run package
99}
100package() {
101 install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
102 install -Dm644 "${srcdir}/${pkgname//-/.}/out/${_pkgname}-linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname%-git}"
103 install -Dm644 "${srcdir}/${pkgname//-/.}/build/icon.png" "${pkgdir}/usr/share/pixmaps/${pkgname%-git}.png"
104 install -Dm644 "${srcdir}/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
105 install -Dm644 "${srcdir}/${pkgname//-/.}/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
106}
107

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion