AUR AI Reviewer

Review Results

Version #1772 of firefox-nightly · commit 667782cbab53 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #434

Comment

The only change in this .SRCINFO hunk is a pkgver bump for firefox-nightly from one upstream nightly snapshot to a newer one. There are no changes to sources, checksums, build steps, install scripts, permissions, or package metadata that would introduce persistence, privilege escalation, or integrity issues. On its face this is a routine version update with no security red flags in the provided diff.

@@ -1,6 +1,6 @@
 pkgbase = firefox-nightly
 	pkgdesc = Fast, Private & Safe Web Browser (Nightly version)
-	pkgver = 154.0a1+20260716.1+hfd15e652209e
+	pkgver = 154.0a1+20260718.1+h1daac5fa8f14
 	pkgrel = 1
 	url = https://www.mozilla.org/firefox/channel/desktop/#nightly
 	arch = x86_64
Risk 0/5 · Safe .SRCINFO
Result #435

Comment

The .SRCINFO change only removes two source entries and their corresponding checksums. This is a metadata-only update and does not introduce any new sources, commands, permissions, or install-time behavior. The removed entries appear to be patch files, so the main effect is that the package will no longer reference them; that is not a security concern by itself in this diff. No red flags for integrity, persistence, privilege escalation, or network fetches are present in the reviewed hunk.

@@ -73,22 +73,16 @@ pkgbase = firefox-nightly
 	source = firefox-nightly.desktop
 	source = org.mozilla.firefox-nightly.metainfo.xml
 	source = 0001-Install-under-remoting-name.patch
-	source = 0002-Bug-2055018-Add-some-missing-X11UndefineNone-include.patch
-	source = 0003-Bug-2055288-Add-missing-include-cstdint-to-DataChann.patch
 	validpgpkeys = 14F26682D0916CDD81E37B6D61B7B526D98F0353
 	sha256sums = SKIP
 	sha256sums = cb00ea359d6daf37900102307be4f515f1b7ef9c98825c64cc55bb562449d0d8
 	sha256sums = 4304902899987928ea51b7020fb1298b01fa77e327ef66ab00b061f767042b9f
 	sha256sums = 9649563e8703b4f4b43469029fe20e3bd0c1209dbaa4c2d664c00e089abd7fa0
 	sha256sums = 844423079aa1ffc5f6ee66df2f43d27879d2a761073939747945da5409bec191
-	sha256sums = add89c5abc3463548b4a401f5cde7b94df67dfe19fea09864db238dbb2681648
-	sha256sums = f1151ff907231aacf604a71c21dc17259146eb6c51d7ea01a7d728e19e62f07d
 	b2sums = SKIP
 	b2sums = f2a9cfb758692584dd8057ab30d0ed9d22f5356d0021e1c8111a061866ee66d6b2d891351e11064f904fe8c90032e78f9def61ed54ae4208c8be4de6b4226277
 	b2sums = 9c748d4c330d37d10862c73b3092c0d4308030fb62ca80da56ba9b3c3350ba4d779570308d1dd8e2c7d873f269654b72030702c5abc772aabfdfe7f39320a8b9
 	b2sums = 561d6fd3b394eee3242c1db12c0520e865488b3e5c1943a398994857b1fcad520ed4387ea93bc9402356649a0b3db6911bcd3a9f8d388bbe88a58a2efec0aa14
 	b2sums = 70e8bfd40bf23afa3f6de2d975aa69043cb88ae14b625702b754cd3de56215be159cf69ba4ed522ca7122b8bbdb50cfe763694e7c7595f2fdcec40bab5e2739f
-	b2sums = 457f9d30311823107177558872a83ce2742de4d09b67f138e7914bfa73ca51c262cf1a8650b29d7d7e0d60ea8ce34375cc93ef0541ebdee3421985df3035d783
-	b2sums = 6421e6a2e5a02cd079ed00358373051e7a2380e9b97f45b181f6bb7267701325f232e18ef725f388f4ed0e4f56c94a08b074f10587b2f7c146192cf781fc81c6
 
 pkgname = firefox-nightly
Risk 0/5 · Safe PKGBUILD
Result #436

Comment

The change only bumps pkgver in PKGBUILD from one Firefox Nightly snapshot to another. No build logic, sources, checksums, install scripts, permissions, or dependencies were altered in the provided hunk. On its face this is a routine version update with no security-relevant red flags in the diff shown.

@@ -3,7 +3,7 @@
 # Contributor: Jakub Schmidtke <sjakub@gmail.com>
 
 pkgname=firefox-nightly
-pkgver=154.0a1+20260716.1+hfd15e652209e
+pkgver=154.0a1+20260718.1+h1daac5fa8f14
 pkgrel=1
 pkgdesc="Fast, Private & Safe Web Browser (Nightly version)"
 url="https://www.mozilla.org/firefox/channel/desktop/#nightly"
Risk 1/5 · Low PKGBUILD
Result #437

Comment

Risk score 1/5. The change only removes two patch files from the PKGBUILD source list and their checksums, while leaving the package build logic otherwise unchanged. I did not find any new network fetches, privilege escalation, install-script changes, or suspicious packaging behavior in the diff. The removed patches appear to be ordinary upstream compatibility fixes for build fallout, so dropping them is more likely to cause a build failure or regression than a security issue. No high-confidence supply-chain or persistence concern is introduced by this hunk.

@@ -89,10 +89,6 @@ source=(
 
   # Make different channels installable in parallel
   0001-Install-under-remoting-name.patch
-
-  # Fix fallout from https://bugzilla.mozilla.org/show_bug.cgi?id=2054311
-  0002-Bug-2055018-Add-some-missing-X11UndefineNone-include.patch
-  0003-Bug-2055288-Add-missing-include-cstdint-to-DataChann.patch
 )
 validpgpkeys=(
   # Mozilla Software Releases <release@mozilla.com>
Risk 0/5 · Safe PKGBUILD
Result #438

Comment

The change only removes two patch sources and their checksums from PKGBUILD, alongside a pkgver bump. I do not see any new code execution, network access, privilege changes, or suspicious sources introduced by this diff. The removed patches appear to have been temporary build fixes, so their deletion may affect build correctness but not security. Overall this looks low risk from a security perspective.

@@ -103,16 +99,12 @@ sha256sums=('SKIP'
             'cb00ea359d6daf37900102307be4f515f1b7ef9c98825c64cc55bb562449d0d8'
             '4304902899987928ea51b7020fb1298b01fa77e327ef66ab00b061f767042b9f'
             '9649563e8703b4f4b43469029fe20e3bd0c1209dbaa4c2d664c00e089abd7fa0'
-            '844423079aa1ffc5f6ee66df2f43d27879d2a761073939747945da5409bec191'
-            'add89c5abc3463548b4a401f5cde7b94df67dfe19fea09864db238dbb2681648'
-            'f1151ff907231aacf604a71c21dc17259146eb6c51d7ea01a7d728e19e62f07d')
+            '844423079aa1ffc5f6ee66df2f43d27879d2a761073939747945da5409bec191')
 b2sums=('SKIP'
         'f2a9cfb758692584dd8057ab30d0ed9d22f5356d0021e1c8111a061866ee66d6b2d891351e11064f904fe8c90032e78f9def61ed54ae4208c8be4de6b4226277'
         '9c748d4c330d37d10862c73b3092c0d4308030fb62ca80da56ba9b3c3350ba4d779570308d1dd8e2c7d873f269654b72030702c5abc772aabfdfe7f39320a8b9'
         '561d6fd3b394eee3242c1db12c0520e865488b3e5c1943a398994857b1fcad520ed4387ea93bc9402356649a0b3db6911bcd3a9f8d388bbe88a58a2efec0aa14'
-        '70e8bfd40bf23afa3f6de2d975aa69043cb88ae14b625702b754cd3de56215be159cf69ba4ed522ca7122b8bbdb50cfe763694e7c7595f2fdcec40bab5e2739f'
-        '457f9d30311823107177558872a83ce2742de4d09b67f138e7914bfa73ca51c262cf1a8650b29d7d7e0d60ea8ce34375cc93ef0541ebdee3421985df3035d783'
-        '6421e6a2e5a02cd079ed00358373051e7a2380e9b97f45b181f6bb7267701325f232e18ef725f388f4ed0e4f56c94a08b074f10587b2f7c146192cf781fc81c6')
+        '70e8bfd40bf23afa3f6de2d975aa69043cb88ae14b625702b754cd3de56215be159cf69ba4ed522ca7122b8bbdb50cfe763694e7c7595f2fdcec40bab5e2739f')
 
 # Google API keys (see https://www.chromium.org/developers/how-tos/api-keys)
 # Note: These are for Arch Linux use ONLY. For your own distribution, please