ytdl-desktop

maintainer zxp19821005 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The `yarn add -D @electron-forge/plugin-local-electron` call installs a package from the npm registry that isn't pinned in the source's yarn.lock. However, `@electron-forge/plugin-local-electron` is a well-known, official package from the Electron Forge project (published by the Electron maintainers on the official npm registry), not from a personal or unofficial host. Its purpose here is legitimate: it allows using the system-installed Electron binary instead of downloading one. The pattern of adding it dynamically rather than having it in package.json is sloppy packaging practice (no version pin, no integrity check), but the package itself is from a trusted, well-maintained ecosystem source. This is a low-severity concern (unpinned dependency from npm) rather than a medium supply-chain risk, since the npm registry and the Electron Forge organization are not 'unofficial or personal hosts'. The overall PKGBUILD also uses nvm to manage Node versions locally, uses git+tag source, and the build flow is standard for Electron Forge projects targeting system Electron.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 75%): The `yarn add -D @electron-forge/plugin-local-electron` call installs a package from the npm registry that isn't pinned in the source's yarn.lock. However, `@electron-forge/plugin-local-electron` is a well-known, official package from the Electron Forge project (published by the Electron maintainers on the official npm registry), not from a personal or unofficial host. Its purpose here is legitimate: it allows using the system-installed Electron binary instead of downloading one. The pattern of adding it dynamically rather than having it in package.json is sloppy packaging practice (no version pin, no integrity check), but the package itself is from a trusted, well-maintained ecosystem source. This is a low-severity concern (unpinned dependency from npm) rather than a medium supply-chain risk, since the npm registry and the Electron Forge organization are not 'unofficial or personal hosts'. The overall PKGBUILD also uses nvm to manage Node versions locally, uses git+tag source, and the build flow is standard for Electron Forge projects targeting system Electron.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:76 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=ytdl-desktop
3_pkgname='Youtube Downloader Desktop'
4pkgver=1.0.0
5_electronversion=25
6_nodeversion=20
7pkgrel=10
8pkgdesc="Youtube Downloader Desktop.(Use system-wide electron)"
9arch=('x86_64')
10url="https://github.com/kayy0812/ytdl-desktop"
11license=('MIT')
12conflicts=("${pkgname}")
13depends=(
14 "electron${_electronversion}"
15)
16makedepends=(
17 'gendesk'
18 'npm'
19 'yarn'
20 'nvm'
21 'curl'
22 'git'
23)
24source=(
25 "${pkgname}-${pkgver}::git+${url}#tag=v${pkgver}"
26 "${pkgname}.sh"
27)
28sha256sums=('c2e680a19f780b512728a8d142b4fab89a9c6f492936234f4470cf04dc1c4c3c'
29 '291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
30_ensure_local_nvm() {
31 local NVM_DIR="${srcdir}/.nvm"
32 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
33 nvm install "${_nodeversion}"
34 nvm use "${_nodeversion}"
35}
36prepare() {
37 cd "${srcdir}/${pkgname}-${pkgver}"
38 sed -i -e "
39 s/@electronversion@/${_electronversion}/g
40 s/@appname@/${pkgname}/g
41 s/@runname@/app.asar/g
42 s/@cfgdirname@/${pkgname}/g
43 s/@options@//g
44 " "${srcdir}/${pkgname}.sh"
45 _ensure_local_nvm
46 gendesk -f -n -q \
47 --pkgname="${pkgname}" \
48 --pkgdesc="${pkgdesc}" \
49 --categories="Utility" \
50 --name="${_pkgname}" \
51 --exec="${pkgname} %U"
52 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
53 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
54 HOME="${srcdir}/.electron-gyp"
55 mkdir -p "${srcdir}/.electron-gyp"
56 if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
57 {
58 echo -e '\n'
59 echo 'registry "https://registry.npmmirror.com"'
60 echo 'electron_mirror "https://registry.npmmirror.com/-/binary/electron/"'
61 echo 'electron_builder_binaries_mirror "https://registry.npmmirror.com/-/binary/electron-builder-binaries/"'
62 echo "cacheFolder "${srcdir}"/.yarn/cache"
63 echo "pluginsFolder "${srcdir}"/.yarn/plugins"
64 echo "globalFolder "${srcdir}"/.yarn/global"
65 echo 'useHardlinks true'
66 #echo 'buildFromSource true'
67 echo 'linkWorkspacePackages true'
68 echo 'fetchRetries 3'
69 echo 'fetchRetryTimeout 10000'
70 echo 'networkConcurrency 10'
71 } >> .yarnrc
72 find ./ -type f -name "yarn.lock" -exec sed -i "s/registry.yarnpkg.com/registry.npmmirror.com/g" {} +
73 fi
74 sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
75 NODE_ENV=development yarn install --cache-folder "${srcdir}/.yarn_cache"
76 NODE_ENV=development yarn add -D @electron-forge/plugin-local-electron
77}
78build() {
79 cd "${srcdir}/${pkgname}-${pkgver}"
80 local electronDist="/usr/lib/electron${_electronversion}"
81 sed -i -e "/^[[:space:]]*plugins:[[:space:]]*\[.*\$/a\\
82 {\\
83 name: \"@electron-forge/plugin-local-electron\",\\
84 config: {\\
85 electronPath: \"${electronDist}\"\\
86 }\\
87 }," forge.config.js
88 NODE_ENV=production yarn run package
89}
90package() {
91 install -Dm755 "${srcdir}/${pkgname}.sh" "${pkgdir}/usr/bin/${pkgname}"
92 install -Dm644 "${srcdir}/${pkgname}-${pkgver}/out/${pkgname}-linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname}"
93 cp -Pr --no-preserve=ownership "${srcdir}/${pkgname}-${pkgver}/out/${pkgname}-linux-"*/resources/app.asar.unpacked "${pkgdir}/usr/lib/${pkgname}"
94 install -Dm644 "${srcdir}/${pkgname}-${pkgver}/${pkgname}.desktop" -t "${pkgdir}/usr/share/applications"
95 install -Dm644 "${srcdir}/${pkgname}-${pkgver}/out/${pkgname}-linux-"*/LICENSE* -t "${pkgdir}/usr/share/licenses/${pkgname}"
96}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion