visual-studio-code-bin

LOW
maintainer dcelasun 1710 votes scanned 2026-10-05 23:40:58.404909
View on AUR

Triggered rules

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:26 source_x86_64=(code_${pkgver}_amd64.deb::https://update.code.visualstudio.com/${pkgver}/linux-deb-x64/stable)

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: D. Can Celasun <can[at]dcc[dot]im>
2
3pkgname=visual-studio-code-bin
4_pkgname=visual-studio-code
5pkgver=1.140.0
6pkgrel=1
7pkgdesc="Visual Studio Code (vscode): Editor for building and debugging modern web and cloud applications (official binary version)"
8arch=('x86_64' 'aarch64' 'armv7h')
9url="https://code.visualstudio.com/"
10license=('custom: commercial')
11provides=('code' 'vscode')
12conflicts=('code')
13# Upstream has signature verification for extensions and stripping breaks it
14# See https://github.com/microsoft/vscode/issues/223455#issuecomment-2610001754
15options=(!strip)
16install=$pkgname.install
17# lsof: needed for terminal splitting, see https://github.com/Microsoft/vscode/issues/62991
18# xdg-utils: needed for opening web links with xdg-open
19depends=(libxkbfile gnupg gtk3 libsecret nss gcc-libs libnotify libxss glibc lsof shared-mime-info xdg-utils alsa-lib)
20optdepends=('glib2: Needed for move to trash functionality'
21 'libdbusmenu-glib: Needed for KDE global menu'
22 'org.freedesktop.secrets: Needed for settings sync'
23 # See https://github.com/MicrosoftDocs/live-share/issues/4650
24 'icu69: Needed for live share' )
25source=(${_pkgname}-bin.sh)
26source_x86_64=(code_${pkgver}_amd64.deb::https://update.code.visualstudio.com/${pkgver}/linux-deb-x64/stable)
27source_aarch64=(code_${pkgver}_arm64.deb::https://update.code.visualstudio.com/${pkgver}/linux-deb-arm64/stable)
28source_armv7h=(code_${pkgver}_armhf.deb::https://update.code.visualstudio.com/${pkgver}/linux-deb-armhf/stable)
29sha256sums=('bd0d9edf69283ebdf4e73e0a7b168d2fcf50acbd01f63674cad93ed4fe42fdad')
30sha256sums_x86_64=('e5ddfa528d68ce907c92cba18ed4edd7420874fe828cbaaf8e4484aa33530c3b')
31sha256sums_aarch64=('e48fc67195d140081bf9363d34dabf07d348e3bf1e78380dfd6abb11e346a9c3')
32sha256sums_armv7h=('0dac80330756b08d9bd586f79e5cb167019f6fa513a752321ce83cdd0a138c44')
33
34package() {
35 bsdtar -xf data.tar.xz -C "${pkgdir}/"
36
37 install -d "${pkgdir}/usr/bin"
38 install -d "${pkgdir}/usr/share/licenses/${pkgname}"
39
40 ln -s /usr/share/code/resources/app/LICENSE.rtf \
41 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.rtf"
42
43 # Launcher
44 install -m755 "${srcdir}/${_pkgname}-bin.sh" "${pkgdir}/usr/bin/code"
45
46 # Fix the desktop entries
47 sed -i \
48 -e 's/^\(Exec=\)[^ ]*/\1code/g' \
49 "${pkgdir}"/usr/share/applications/*.desktop
50
51 # setuid on chrome-sandbox
52 # Comment out if using a kernel without user namespaces, like linux-hardened
53 chmod u-s "${pkgdir}/usr/share/code/chrome-sandbox"
54}
55

Changes since previous scan

--- PKGBUILD @ 2026-09-26 00:12
+++ PKGBUILD @ 2026-10-05 23:40
@@ -2,7 +2,7 @@
pkgname=visual-studio-code-bin
_pkgname=visual-studio-code
-pkgver=1.139.1
+pkgver=1.140.0
pkgrel=1
pkgdesc="Visual Studio Code (vscode): Editor for building and debugging modern web and cloud applications (official binary version)"
arch=('x86_64' 'aarch64' 'armv7h')
@@ -27,9 +27,9 @@
source_aarch64=(code_${pkgver}_arm64.deb::https://update.code.visualstudio.com/${pkgver}/linux-deb-arm64/stable)
source_armv7h=(code_${pkgver}_armhf.deb::https://update.code.visualstudio.com/${pkgver}/linux-deb-armhf/stable)
sha256sums=('bd0d9edf69283ebdf4e73e0a7b168d2fcf50acbd01f63674cad93ed4fe42fdad')
-sha256sums_x86_64=('cc8e35cf69ff4c7e515e19fa981bf6aba41f61ddb61c79370e9fe460c5dbaf8b')
-sha256sums_aarch64=('53cdf61fd870ec9663ea7baa5e4f79014acafc36d8c45b2678a8ce80d72d737d')
-sha256sums_armv7h=('09afa2bcd369ce7a8231a297bed487a9f7aa1ba3776cdac3bfd481d1bb08b708')
+sha256sums_x86_64=('e5ddfa528d68ce907c92cba18ed4edd7420874fe828cbaaf8e4484aa33530c3b')
+sha256sums_aarch64=('e48fc67195d140081bf9363d34dabf07d348e3bf1e78380dfd6abb11e346a9c3')
+sha256sums_armv7h=('0dac80330756b08d9bd586f79e5cb167019f6fa513a752321ce83cdd0a138c44')
package() {
bsdtar -xf data.tar.xz -C "${pkgdir}/"

Scan history

Scanned at (UTC)SeverityRules
2026-10-05 23:40:58 Low 1
2026-09-26 00:12:15 Clean 2
2026-09-25 15:12:17 Low 1
2026-09-24 00:24:14 Clean 2
2026-09-23 15:40:39 Low 1
2026-09-17 00:27:14 Clean 2
2026-09-16 15:22:50 Low 1
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 23:20:11 Low 2
2026-09-09 00:04:09 Clean 2
2026-09-08 21:18:22 Low 1
2026-09-04 00:03:13 Clean 2
2026-09-03 15:53:41 Low 1
2026-09-03 00:15:47 Clean 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion