zima-linux-client
The npx command is used to run @electron/rebuild locally against already-installed dependencies, not to execute arbitrary remote code; the source is a git checkout from the project's official repository.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The npx command is used to run @electron/rebuild locally against already-installed dependencies, not to execute arbitrary remote code; the source is a git checkout from the project's official repository.
1 higher static finding superseded - not the current verdict (shown for transparency)
remote_code_tool
`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.
-
PKGBUILD:73
npx @electron/rebuild -v "$electron_version"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Your Name <your.email@example.com>
pkgname=zima-linux-client
pkgver=0.9.23
pkgrel=1
pkgdesc="Modern Desktop Client for ZimaOS with integrated ZeroTier and SMB management"
arch=('x86_64')
url="https://github.com/chicohaager/zima-linux-client"
license=('MIT')
depends=(
'electron'
'fuse2'
'smbclient'
'nss'
'gtk3'
'libxkbcommon'
'libxcb'
'libx11'
'libxcomposite'
'libxdamage'
'libxext'
'libxfixes'
'libxrandr'
'alsa-lib'
'at-spi2-core'
'libcups'
'libdrm'
'mesa'
'libsecret'
'nodejs'
)
makedepends=('npm' 'nodejs' 'git' 'libsecret' 'python')
install=zima-linux-client.install
source=(
"git+https://github.com/chicohaager/zima-linux-client.git#tag=v${pkgver}"
"zima-linux-client.sh"
"zima-linux-client.desktop"
)
sha256sums=(
'SKIP'
'SKIP'
'SKIP'
)
build() {
cd "$srcdir/$pkgname"
# Install dependencies
npm install
# Build the application
npm run build
}
package() {
cd "$srcdir/$pkgname"
# Create directories
install -dm755 "$pkgdir/usr/lib/$pkgname"
install -dm755 "$pkgdir/usr/bin"
install -dm755 "$pkgdir/usr/share/applications"
install -dm755 "$pkgdir/usr/share/icons/hicolor/512x512/apps"
install -dm755 "$pkgdir/usr/lib/$pkgname/resources"
install -dm755 "$pkgdir/usr/lib/systemd/user"
# Copy built files (preserve dist directory structure)
cp -r dist "$pkgdir/usr/lib/$pkgname/"
cp package.json "$pkgdir/usr/lib/$pkgname/"
# Install production dependencies only and rebuild for electron
cd "$pkgdir/usr/lib/$pkgname"
npm install --omit=dev
local electron_version=$(electron --version | sed 's/v//')
npx @electron/rebuild -v "$electron_version"
# Remove unnecessary files to reduce package size
find "$pkgdir/usr/lib/$pkgname/node_modules" -name "*.md" -delete 2>/dev/null || true
find "$pkgdir/usr/lib/$pkgname/node_modules" -name "*.ts" ! -name "*.d.ts" -delete 2>/dev/null || true
find "$pkgdir/usr/lib/$pkgname/node_modules" -type d -name "test" -exec rm -rf {} + 2>/dev/null || true
find "$pkgdir/usr/lib/$pkgname/node_modules" -type d -name "tests" -exec rm -rf {} + 2>/dev/null || true
find "$pkgdir/usr/lib/$pkgname/node_modules" -type d -name "__tests__" -exec rm -rf {} + 2>/dev/null || true
cd "$srcdir/$pkgname"
# Copy ZeroTier binaries
cp -r bin "$pkgdir/usr/lib/$pkgname/"
# Copy resources
cp -r resources/*.service "$pkgdir/usr/lib/$pkgname/resources/" 2>/dev/null || true
cp -r resources/*.sh "$pkgdir/usr/lib/$pkgname/resources/" 2>/dev/null || true
cp -r resources/copyright "$pkgdir/usr/lib/$pkgname/resources/" 2>/dev/null || true
# Install icon
install -Dm644 icon.png "$pkgdir/usr/share/icons/hicolor/512x512/apps/$pkgname.png"
# Install launcher script
install -Dm755 "$srcdir/zima-linux-client.sh" "$pkgdir/usr/bin/$pkgname"
# Install desktop file
install -Dm644 "$srcdir/zima-linux-client.desktop" "$pkgdir/usr/share/applications/$pkgname.desktop"
# Install systemd user service
install -Dm644 resources/zima-zerotier.service "$pkgdir/usr/lib/systemd/user/zima-zerotier.service"
# Install license
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |