wavy-git

maintainer zxp19821005 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The `yarn add -D @electron-forge/plugin-local-electron` call installs a package from the npm registry that is not listed in the project's package.json. However, `@electron-forge/plugin-local-electron` is a well-known, official package from the Electron Forge project (published by the Electron maintainers on the official npm registry), not from a personal or unofficial host. Its purpose here is clearly legitimate: it allows building with a system-installed Electron binary instead of downloading one, which is exactly the pattern used by many AUR Electron packages. The package is fetched from the standard npm registry (or its Chinese mirror), not from a personal/unofficial source. This is a common AUR pattern for packaging Electron apps against system Electron. The supply-chain risk is no greater than any other npm dependency install during build. The overall concern is low — it's slightly sloppy (the dependency could be added to package.json upstream or patched in), but not a meaningful security risk.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 80%): The `yarn add -D @electron-forge/plugin-local-electron` call installs a package from the npm registry that is not listed in the project's package.json. However, `@electron-forge/plugin-local-electron` is a well-known, official package from the Electron Forge project (published by the Electron maintainers on the official npm registry), not from a personal or unofficial host. Its purpose here is clearly legitimate: it allows building with a system-installed Electron binary instead of downloading one, which is exactly the pattern used by many AUR Electron packages. The package is fetched from the standard npm registry (or its Chinese mirror), not from a personal/unofficial source. This is a common AUR pattern for packaging Electron apps against system Electron. The supply-chain risk is no greater than any other npm dependency install during build. The overall concern is low — it's slightly sloppy (the dependency could be added to package.json upstream or patched in), but not a meaningful security risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:82 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=wavy-git
3_pkgname=Wavy
4pkgver=1.1.3.r0.ga69c717
5_electronversion=28
6_nodeversion=22
7pkgrel=1
8pkgdesc="A simple protocol testing tool that supports various connection types(now serial port only).(Use system-wide electron)"
9arch=('x86_64')
10url="https://github.com/novrain/wavy"
11license=('MIT')
12provides=("${pkgname%-git}=${pkgver%.r*}")
13conflicts=("${pkgname%-git}")
14depends=(
15 "electron${_electronversion}"
16)
17makedepends=(
18 'npm'
19 'nvm'
20 'git'
21 'curl'
22 'yarn'
23 'gendesk'
24)
25source=(
26 "${pkgname//-/.}::git+${url}.git"
27 "${pkgname%-git}.sh"
28)
29sha256sums=('SKIP'
30 '291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
31pkgver() {
32 cd "${srcdir}/${pkgname//-/.}"
33 set -o pipefail
34 git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
35 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
36}
37_ensure_local_nvm() {
38 local NVM_DIR="${srcdir}/.nvm"
39 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
40 nvm install "${_nodeversion}"
41 nvm use "${_nodeversion}"
42}
43prepare() {
44 cd "${srcdir}/${pkgname//-/.}"
45 sed -i -e "
46 s/@electronversion@/${_electronversion}/g
47 s/@appname@/${pkgname%-git}/g
48 s/@runname@/app.asar/g
49 s/@cfgdirname@/${pkgname%-git}/g
50 s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
51 " "${srcdir}/${pkgname%-git}.sh"
52 _ensure_local_nvm
53 gendesk -q -f -n \
54 --pkgname="${pkgname%-git}" \
55 --pkgdesc="${pkgdesc}" \
56 --categories="Utility" \
57 --name="${_pkgname}" \
58 --exec="${pkgname%-git} %U"
59 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
60 HOME="${srcdir}/.electron-gyp"
61 mkdir -p "${srcdir}/.electron-gyp"
62 if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
63 {
64 echo -e '\n'
65 echo 'registry "https://registry.npmmirror.com"'
66 echo 'electron_mirror "https://registry.npmmirror.com/-/binary/electron/"'
67 echo 'electron_builder_binaries_mirror "https://registry.npmmirror.com/-/binary/electron-builder-binaries/"'
68 echo "cacheFolder "${srcdir}"/.yarn/cache"
69 echo "pluginsFolder "${srcdir}"/.yarn/plugins"
70 echo "globalFolder "${srcdir}"/.yarn/global"
71 echo 'useHardlinks true'
72 #echo 'buildFromSource true'
73 echo 'linkWorkspacePackages true'
74 echo 'fetchRetries 3'
75 echo 'fetchRetryTimeout 10000'
76 echo 'networkConcurrency 10'
77 } >> .yarnrc
78 find ./ -type f -name "yarn.lock" -exec sed -i "s/47.122.4.61:4873/registry.npmmirror.com/g;s/registry.yarnpkg.com/registry.npmmirror.com/g" {} +
79 fi
80 sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
81 NODE_ENV=development yarn install --cache-folder "${srcdir}/.yarn_cache"
82 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
83}
84build() {
85 cd "${srcdir}/${pkgname//-/.}"
86 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
87 local electronDist="/usr/lib/electron${_electronversion}"
88 sed -i "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
89 {\\
90 name: \"@electron-forge/plugin-local-electron\",\\
91 config: {\\
92 electronPath: \'${electronDist}\',\\
93 },\\
94 }," forge.config.*
95 NODE_ENV=production yarn run electron:build
96 NODE_ENV=production yarn run vite:build
97 NODE_ENV=production yarn run forge:package
98 rm -rf "${srcdir}/${pkgname//-/.}/out/${_pkgname}-linux-"*/resources/app.asar.unpacked/node_modules/@serialport/bindings-cpp/prebuilds/{android-*,darwin-*,linux-arm*,win32-*}
99}
100package() {
101 install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
102 install -Dm644 "${srcdir}/${pkgname//-/.}/out/${_pkgname}-linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname%-git}"
103 cp -Pr --no-preserve=ownership "${srcdir}/${pkgname//-/.}/out/${_pkgname}-linux-"*/resources/app.asar.unpacked "${pkgdir}/usr/lib/${pkgname%-git}"
104 install -Dm644 "${srcdir}/${pkgname//-/.}/src/main/assets/tray-darwinTemplate.png" "${pkgdir}/usr/share/pixmaps/${pkgname%-git}.png"
105 install -Dm644 "${srcdir}/${pkgname//-/.}/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
106 install -Dm644 "${srcdir}/${pkgname//-/.}/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
107}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion