visty-git
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The PKGBUILD builds an Electron video player from its official upstream GitHub source. The yarn install pulls npm dependencies as part of a standard build process — this is normal for Electron/Node.js AUR packages and is not meaningfully different from any other npm-based build. The CN mirror logic conditionally redirects to npmmirror.com (a well-known Chinese npm mirror), which is a common pattern in AUR packages targeting Chinese users. The source is a git clone from the official upstream repo with a versioned shell script launcher. No pre-built binaries are downloaded from unofficial hosts; the package builds from source using the system electron. The 'yarn add @electron-forge/plugin-local-electron' is a standard build tool for packaging with a local electron binary. The cheaper model's concern about yarn install is a false positive for this class of package — it applies equally to virtually every Node.js AUR package. The only real concern is the SKIP checksum on the git source (standard for VCS sources) and the dynamic npm dependency resolution, which is a low-severity sloppy practice but not a targeted supply-chain attack.
1 higher static finding superseded - not the current verdict (shown for transparency)
npm_install_external
Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.
-
PKGBUILD:84
NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
PKGBUILD
1 offending line(s) highlighted# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
pkgname=visty-git
_pkgname=Visty
pkgver=0.0.5.de.r0.g5e7fc1b
_electronversion=38
_nodeversion=22
pkgrel=1
pkgdesc="Simple Video Player based on Electron.(Use system-wide electron)"
arch=('any')
url="https://github.com/fiahfy/visty"
license=('MIT')
provides=("${pkgname%-git}=${pkgver%.r*}")
conflicts=("${pkgname%-git}")
depends=(
"electron${_electronversion}"
)
makedepends=(
'npm'
'nvm'
'git'
'curl'
'gendesk'
'yarn'
)
source=(
"${pkgname//-/.}::git+${url}.git"
"${pkgname%-git}.sh"
)
sha256sums=('SKIP'
'31ad33b633744f5361abd964be306cea53ae1050e760c787115f7eca60045ae6')
pkgver() {
cd "${srcdir}/${pkgname//-/.}"
set -o pipefail
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
}
_ensure_local_nvm() {
local NVM_DIR="${srcdir}/.nvm"
source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
nvm install "${_nodeversion}"
nvm use "${_nodeversion}"
}
_get_electron_version() {
_elec_ver="$(grep -m 1 '"electron":' "${srcdir}/${pkgname//-/.}/package.json" | cut -d'"' -f4 | tr -d '^' | cut -d. -f1)"
echo -e "The electron version is: \033[1;31m${_elec_ver}\033[0m"
}
prepare() {
cd "${srcdir}/${pkgname//-/.}"
_get_electron_version
sed -i -e "
s/@electronversion@/${_electronversion}/g
s/@appname@/${pkgname%-git}/g
s/@runname@/app.asar/g
s/@cfgdirname@/${_pkgname}/g
s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
" "${srcdir}/${pkgname%-git}.sh"
gendesk -q -f -n \
--pkgname="${pkgname%-git}" \
--pkgdesc="${pkgdesc}" \
--categories="AudioVideo" \
--name="${_pkgname}" \
--exec="${pkgname%-git} %U"
export ELECTRON_SKIP_BINARY_DOWNLOAD=1
export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
HOME="${srcdir}/.electron-gyp"
mkdir -p "${srcdir}/.electron-gyp"
touch "${srcdir}/.electron-gyp/.yarnrc"
if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
{
echo 'npmRegistryServer: "https://registry.npmmirror.com"'
echo "cacheFolder: "${srcdir}"/.yarn/cache"
echo "globalFolder: "${srcdir}"/.yarn/global"
} >> .yarnrc.yml
export npm_config_electron_mirror=https://registry.npmmirror.com/-/binary/electron/
export npm_config_electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/
fi
_ensure_local_nvm
#find src -type f -exec sed -i "s/process.resourcesPath/\'\/usr\/lib\/${pkgname%-git}\'/g" {} +
sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
_yarnver=`grep "yarn@" package.json | awk '{print $2}' | sed "s/\"//g;s/yarn@//g;s/,//g"`
corepack enable yarn
echo y | yarn version "${_yarnver}"
NODE_ENV=development yarn install
NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
}
build() {
cd "${srcdir}/${pkgname//-/.}"
_ensure_local_nvm
export ELECTRON_SKIP_BINARY_DOWNLOAD=1
local electronDist="/usr/lib/electron${_electronversion}"
sed -i "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
{\\
name: \"@electron-forge/plugin-local-electron\",\\
config: {\\
electronPath: \'${electronDist}\',\\
},\\
}," forge.config.*
NODE_ENV=production yarn run package
}
package() {
install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
install -Dm644 "${srcdir}/${pkgname//-/.}/out/${_pkgname}-linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname%-git}"
install -Dm644 "${srcdir}/${pkgname//-/.}/build/icon.png" "${pkgdir}/usr/share/pixmaps/${pkgname%-git}.png"
install -Dm644 "${srcdir}/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
install -Dm644 "${srcdir}/${pkgname//-/.}/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |