wingdrive-bin

LOW
maintainer bernardopg 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package installs a prebuilt AppImage from the maintainer's GitHub release, which is a common AUR pattern; the AppImage is from a plausible project source, but the low vote count and recent upload give limited community trust, warranting low severity due to supply-chain risk of a single-party binary.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt AppImage from the maintainer's GitHub release, which is a common AUR pattern; the AppImage is from a plausible project source, but the low vote count and recent upload give limited community trust, warranting low severity due to supply-chain risk of a single-party binary.

PKGBUILD

1# Maintainer: Bernardo Gomes <bernardopg@users.noreply.github.com>
2pkgname=wingdrive-bin
3pkgver=2.0.0alpha6
4pkgrel=1
5pkgdesc='WingDrive desktop file manager'
6arch=('x86_64')
7url='https://github.com/bernardopg/wingdrive'
8license=('LicenseRef-FSL-1.1-ALv2' 'GPL-3.0-only')
9depends=('glibc' 'gtk3' 'webkit2gtk-4.1' 'xdotool' 'xdg-utils' 'alsa-lib' 'libpipewire' 'jack' 'libva')
10provides=('wingdrive')
11conflicts=('wingdrive')
12options=('!strip')
13_upstream_version=2.0.0-alpha.6
14source=("WingDrive-2.0.0-alpha.6-x86_64.AppImage::https://github.com/bernardopg/wingdrive/releases/download/v${_upstream_version}/WingDrive-2.0.0-alpha.6-x86_64.AppImage"
15 "LICENSE::https://github.com/bernardopg/wingdrive/releases/download/v${_upstream_version}/LICENSE")
16sha256sums=('8ddd18ce381c10f3e8f5c72dacd16260d8a7ccacd4ac83547ce1b974adb86577' '24e941b64ab9f59b5a7ca1bafb27bd25e550d7d9461c5890482443f5b19b50b8')
17
18prepare() {
19 chmod +x "WingDrive-2.0.0-alpha.6-x86_64.AppImage"
20 "./WingDrive-2.0.0-alpha.6-x86_64.AppImage" --appimage-extract > /dev/null
21 find squashfs-root -type d -exec chmod 755 {} +
22}
23
24package() {
25 install -d "$pkgdir/opt/wingdrive" "$pkgdir/usr/bin"
26 cp -a squashfs-root/. "$pkgdir/opt/wingdrive/"
27 cat > "$pkgdir/usr/bin/wingdrive" <<'WRAPPER'
28#!/bin/sh
29export APPDIR=/opt/wingdrive
30exec "$APPDIR/AppRun" "$@"
31WRAPPER
32 chmod 755 "$pkgdir/usr/bin/wingdrive"
33 install -Dm644 squashfs-root/usr/share/applications/*.desktop "$pkgdir/usr/share/applications/wingdrive.desktop"
34 sed -i 's|^Exec=.*|Exec=wingdrive %U|; s|^TryExec=.*|TryExec=wingdrive|' "$pkgdir/usr/share/applications/wingdrive.desktop"
35 if [[ -d squashfs-root/usr/share/icons ]]; then
36 install -d "$pkgdir/usr/share/icons"
37 cp -a squashfs-root/usr/share/icons/. "$pkgdir/usr/share/icons/"
38 fi
39 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
40 install -Dm644 squashfs-root/usr/lib/WingDrive/NOTICE.md "$pkgdir/usr/share/licenses/$pkgname/NOTICE.md"
41 cp -a squashfs-root/usr/lib/WingDrive/licenses/. "$pkgdir/usr/share/licenses/$pkgname/"
42}
43

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion