Comment
The change only updates the pinned upstream Chrome .deb version in .SRCINFO and refreshes its sha512 checksum. The source remains the official Google HTTPS download URL, with no new build steps, scripts, or packaging logic introduced. I don’t see any added supply-chain, persistence, or privilege-escalation risk in this diff alone.
@@ -21,10 +21,10 @@ pkgbase = google-chrome-dev
provides = google-chrome
options = !emptydirs
options = !strip
- source = https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-unstable/google-chrome-unstable_152.0.7928.2-1_amd64.deb
+ source = https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-unstable/google-chrome-unstable_152.0.7939.5-1_amd64.deb
source = eula_text.html
source = google-chrome-unstable.sh
- sha512sums = 3b6e102119d99cc91670d4a749ba1c902bca724cc92087ad8c6900282f5b844918f8d4cbad244cf7dbb9cd48d81612ba2189d32caa49ba4ee86460439b0859f3
+ sha512sums = 7d5703d247d8428090af1117a4b1a03665c8ab6c9b8c30510ffe9c7fe224fc731ea1599c7f6922d049e358284ce5c15dbd4568a1bc2857e18f7ad606b4813032
sha512sums = a225555c06b7c32f9f2657004558e3f996c981481dbb0d3cd79b1d59fa3f05d591af88399422d3ab29d9446c103e98d567aeafe061d9550817ab6e7eb0498396
sha512sums = 445eb36a588f49af018ded3d852b63e0523ffac20c25be721f3ef4663591256849432bebb3d9f352e4f53cbe1fb77fa67cf8911c9161f826490a21adbdcc81f4