wispr-flow-hyprland

LOW
maintainer kukapu 0 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads prebuilt assets from a non-whitelisted host (dl.wisprflow.com), but they are verified with fixed checksums and used to assemble a desktop application in a standard AUR build process; the source is plausibly official, and no unverified remote code execution occurs.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt assets from a non-whitelisted host (dl.wisprflow.com), but they are verified with fixed checksums and used to assemble a desktop application in a standard AUR build process; the source is plausibly official, and no unverified remote code execution occurs.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:69 "${_nupkg}::https://dl.wisprflow.com/wispr-flow/win32/x64/${_nupkg}"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Albert Alvarez Estelles <114157589+kukapu@users.noreply.github.com>
2
3pkgname=wispr-flow-hyprland
4pkgver=1.6.774
5pkgrel=1
6pkgdesc='Unofficial Wispr Flow desktop client packaged for Omarchy 4 (Hyprland Lua) on Arch'
7arch=('x86_64')
8url='https://github.com/kukapu/whsprflow-arch'
9license=('0BSD AND BSD-3-Clause AND LicenseRef-Proprietary AND MIT AND Unlicense')
10depends=(
11 'alsa-lib'
12 'at-spi2-core'
13 'bash'
14 'cairo'
15 'coreutils'
16 'dbus'
17 'expat'
18 'gawk'
19 'glib2'
20 'glibc'
21 'grep'
22 'gtk3'
23 'hicolor-icon-theme'
24 'hyprland'
25 'jq'
26 'less'
27 'libcups'
28 'libgcc'
29 'libpulse'
30 'libsecret'
31 'libstdc++'
32 'libx11'
33 'libxcb'
34 'libxcomposite'
35 'libxdamage'
36 'libxext'
37 'libxfixes'
38 'libxkbcommon'
39 'libxrandr'
40 'mesa'
41 'nodejs'
42 'nspr'
43 'nss'
44 'pango'
45 'systemd'
46 'systemd-libs'
47 'util-linux'
48 'wl-clipboard'
49 'xdg-utils'
50 'xorg-xwayland'
51)
52makedepends=('asar' 'perl' 'python' 'unzip')
53optdepends=('uwsm: managed Hyprland autostart with wispr-flow --autostart')
54provides=("wispr-flow=${pkgver}")
55conflicts=('wispr-flow')
56options=('!strip' '!debug')
57install=wispr-flow-hyprland.install
58
59_support_commit='d092cfb3344715fcd794091feea9b1dd678df26b'
60_port_commit='6fb43cd809f8319a9e05da4b4e7a2d3264c126ab'
61_electron_version='42.3.0'
62_nupkg="WisprFlow-${pkgver}-full.nupkg"
63_electron_zip="electron-v${_electron_version}-linux-x64.zip"
64_sqlite="node_sqlite3-${CARCH}.node"
65
66source=(
67 "${pkgname}-support-${_support_commit}.tar.gz::https://codeload.github.com/kukapu/whsprflow-arch/tar.gz/${_support_commit}"
68 "${pkgname}-port-${_port_commit}.tar.gz::https://codeload.github.com/wispr-flow-linux/wispr-flow-linux/tar.gz/${_port_commit}"
69 "${_nupkg}::https://dl.wisprflow.com/wispr-flow/win32/x64/${_nupkg}"
70 "${_electron_zip}::https://github.com/electron/electron/releases/download/v${_electron_version}/${_electron_zip}"
71 "${_sqlite}::https://github.com/wispr-flow-linux/native-modules/releases/download/native-v1/${_sqlite}"
72 'wispr-flow.desktop'
73 '70-wispr-flow-input.rules'
74)
75noextract=("${_nupkg}" "${_electron_zip}")
76sha256sums=(
77 'e7433c7291a1828da4572cbfb1e93d7bbe754400bf17a90fbbd1385e599f545c'
78 '365c68a8b3915a643a51634c298ac178cd0e441bd112707878f318cdef8dcac2'
79 '36a33ee649c834d617cc5c90c06d618ffda4062287ce8c064e4837448e4bdddc'
80 '487a667ca6a734b958c16cff1df74d9d44d2c18a6cccdb4dd51f6301a356c420'
81 'c9bd0419f77efb3b5d3a691fda04e265f740ad8dc195f0b56003cdeac92e9a34'
82 '3b65d10698a9c944c5494cfd9a5fa3f04dd7b5a02f8fce0ace9333b6f1646ba5'
83 '3d7d9cab9b2af22cfd60b0dd965ff1b0f6e315e03c203add9f9646ae320bb97d'
84)
85
86build() {
87 local support_dir="$srcdir/whsprflow-arch-${_support_commit}"
88 local port_dir="$srcdir/wispr-flow-linux-${_port_commit}"
89
90 rm -rf -- "$srcdir/runtime"
91 "$support_dir/scripts/assemble-app.sh" \
92 --version "$pkgver" \
93 --nupkg "$srcdir/${_nupkg}" \
94 --electron-zip "$srcdir/${_electron_zip}" \
95 --sqlite "$srcdir/${_sqlite}" \
96 --helper "$support_dir/assets/wispr-flow-linux-helper-${CARCH}" \
97 --port-dir "$port_dir" \
98 --output-dir "$srcdir/runtime" \
99 --asar-bin /usr/bin/asar
100}
101
102check() {
103 local support_dir="$srcdir/whsprflow-arch-${_support_commit}"
104 local app_asar="$srcdir/runtime/resources/app.asar"
105 local sqlite="$srcdir/runtime/resources/app.asar.unpacked/.webpack/main/native_modules/build/Release/node_sqlite3.node"
106 local helper="$srcdir/runtime/resources/Release/wispr-flow-linux-helper"
107 local check_app="$srcdir/check-app"
108 local asar_files="$srcdir/asar-files.txt"
109 local smoke_root="$srcdir/wrapper-smoke"
110 local smoke_output
111
112 [[ $(< "$srcdir/runtime/app-version") == "$pkgver" ]]
113 printf '%s %s\n' \
114 '5f069506ccf51964f05ba6b06b7a1bfbb42cd2a5d64437c965abba628c4b45b0' \
115 "$helper" | sha256sum -c -
116 printf '%s %s\n' \
117 'c9bd0419f77efb3b5d3a691fda04e265f740ad8dc195f0b56003cdeac92e9a34' \
118 "$sqlite" | sha256sum -c -
119
120 /usr/bin/asar list "$app_asar" > "$asar_files"
121 ! grep -qE 'crypt32-|[.]orig$' "$asar_files"
122 rm -rf -- "$check_app"
123 /usr/bin/asar extract "$app_asar" "$check_app"
124 [[ $(node -e 'process.stdout.write(require(process.argv[1]).version)' \
125 "$check_app/package.json") == "$pkgver" ]]
126 local main_bundle="$check_app/.webpack/main/index.js"
127 local marker
128 for marker in \
129 WISPR_LINUX_HIDE_STATUS_WINDOW_SHOW \
130 WISPR_LINUX_HIDE_STATUS_WINDOW_DICTATION \
131 WISPR_LINUX_LOCAL_START_SOUND \
132 WISPR_LINUX_LOCAL_STOP_SOUND \
133 WISPR_LINUX_COMPACT_STATUS_WINDOW \
134 WISPR_LINUX_TRANSIENT_STATUS_HIDE \
135 WISPR_LINUX_STATUS_ZOOM \
136 WISPR_LINUX_STATUS_GEOMETRY \
137 WISPR_LINUX_STATUS_INTERACTIVE \
138 WISPR_LINUX_STATUS_HITTEST \
139 WISPR_LINUX_STATUS_TOUR
140 do
141 grep -qF "$marker" "$main_bundle"
142 done
143
144 rm -rf -- "$smoke_root"
145 mkdir -p "$smoke_root/usr/lib" "$srcdir/check-home" "$srcdir/check-config"
146 ln -s "$srcdir/runtime" "$smoke_root/usr/lib/wispr-flow"
147 smoke_output="$(
148 HOME="$srcdir/check-home" \
149 XDG_CONFIG_HOME="$srcdir/check-config" \
150 WISPR_FLOW_INSTALL_ROOT="$smoke_root" \
151 "$support_dir/bin/wispr-flow" --status
152 )"
153 grep -qF 'Electron principal: 0' <<< "$smoke_output"
154 grep -qF 'Helper: 0' <<< "$smoke_output"
155}
156
157package() {
158 local support_dir="$srcdir/whsprflow-arch-${_support_commit}"
159 local port_dir="$srcdir/wispr-flow-linux-${_port_commit}"
160 local app_dir="$pkgdir/opt/wispr-flow-hyprland/usr/lib/wispr-flow"
161 local license_dir="$pkgdir/usr/share/licenses/$pkgname"
162
163 install -d "$pkgdir/opt/wispr-flow-hyprland/usr/lib"
164 cp -a "$srcdir/runtime" "$app_dir"
165 chmod 4755 "$app_dir/chrome-sandbox"
166
167 install -Dm755 "$support_dir/bin/wispr-flow" \
168 "$support_dir/bin/wispr-flow-configure" -t "$pkgdir/usr/bin"
169 install -Dm644 "$srcdir/wispr-flow.desktop" \
170 "$pkgdir/usr/share/applications/wispr-flow.desktop"
171 install -Dm644 "$srcdir/70-wispr-flow-input.rules" \
172 "$pkgdir/usr/lib/udev/rules.d/70-wispr-flow-input.rules"
173 install -Dm644 "$app_dir/resources/assets/logos/flow-symbol.svg" \
174 "$pkgdir/usr/share/icons/hicolor/scalable/apps/wispr-flow.svg"
175
176 install -Dm644 "$support_dir/LICENSE" "$license_dir/SUPPORT-0BSD"
177 install -Dm644 "$support_dir/assets/UNLICENSE" "$license_dir/HELPER-UNLICENSE"
178 install -Dm644 "$port_dir/UNLICENSE" "$license_dir/PORT-UNLICENSE"
179 install -Dm644 "$app_dir/LICENSE" "$license_dir/ELECTRON-MIT"
180 install -Dm644 "$app_dir/LICENSES.chromium.html" \
181 "$license_dir/ELECTRON-THIRD-PARTY.html"
182 cat > "$license_dir/WISPR-FLOW-PROPRIETARY-NOTICE" <<'EOF'
183The Wispr Flow client is proprietary software and remains subject to Wispr's
184terms and policies. This community package and its support code grant no
185license to the client. See https://wisprflow.ai/terms-of-service/ before use.
186EOF
187}
188

Changes since previous scan

--- PKGBUILD @ 2026-09-25 00:03
+++ PKGBUILD @ 2026-10-02 00:00
@@ -1,8 +1,8 @@
# Maintainer: Albert Alvarez Estelles <114157589+kukapu@users.noreply.github.com>
pkgname=wispr-flow-hyprland
-pkgver=1.6.447
-pkgrel=2
+pkgver=1.6.774
+pkgrel=1
pkgdesc='Unofficial Wispr Flow desktop client packaged for Omarchy 4 (Hyprland Lua) on Arch'
arch=('x86_64')
url='https://github.com/kukapu/whsprflow-arch'
@@ -56,7 +56,7 @@
options=('!strip' '!debug')
install=wispr-flow-hyprland.install
-_support_commit='71ea2acdf0588b7aa58b69d459a3857e12ce3a7f'
+_support_commit='d092cfb3344715fcd794091feea9b1dd678df26b'
_port_commit='6fb43cd809f8319a9e05da4b4e7a2d3264c126ab'
_electron_version='42.3.0'
_nupkg="WisprFlow-${pkgver}-full.nupkg"
@@ -74,9 +74,9 @@
)
noextract=("${_nupkg}" "${_electron_zip}")
sha256sums=(
- 'c701c97a9bb2640dec3b93b58c042479a2d266d800a4f28425371e447ebbe4f1'
+ 'e7433c7291a1828da4572cbfb1e93d7bbe754400bf17a90fbbd1385e599f545c'
'365c68a8b3915a643a51634c298ac178cd0e441bd112707878f318cdef8dcac2'
- 'c5a6175c74028c30b11c9a96a295df1b47780929ceaf3753a96ffa855b591f03'
+ '36a33ee649c834d617cc5c90c06d618ffda4062287ce8c064e4837448e4bdddc'
'487a667ca6a734b958c16cff1df74d9d44d2c18a6cccdb4dd51f6301a356c420'
'c9bd0419f77efb3b5d3a691fda04e265f740ad8dc195f0b56003cdeac92e9a34'
'3b65d10698a9c944c5494cfd9a5fa3f04dd7b5a02f8fce0ace9333b6f1646ba5'

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 21:13:17 Medium 1
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion