Comment
The change is a straightforward version bump in .SRCINFO from Joplin 3.6.14 to 3.6.15, with the source URLs still pointing to the official upstream GitHub release and license file over HTTPS. No new sources, scripts, build logic, or privilege-related artifacts are introduced in this diff. The only security-relevant change is the updated checksum, which is expected for a new upstream release. Based on this diff alone, I see no evidence of supply-chain tampering or packaging abuse.
@@ -8,9 +8,9 @@ pkgbase = joplin-appimage
depends = fuse2
conflicts = joplin-desktop
options = !strip
- source = https://github.com/laurent22/joplin/releases/download/v3.6.14/Joplin-3.6.14.AppImage
- source = https://github.com/laurent22/joplin/raw/v3.6.14/LICENSE
- sha512sums = c445a41671c2c8cec6a04373adbe32880310fe4945a26b6e3978781212af1bb580c3f06bb8fcb187b524f0312fc3e89efdb8238aac97a4cb741b869f2163355d
+ source = https://github.com/laurent22/joplin/releases/download/v3.6.15/Joplin-3.6.15.AppImage
+ source = https://github.com/laurent22/joplin/raw/v3.6.15/LICENSE
+ sha512sums = 1acf483b4d8cc1c56b277bf02c86b04fb2b466b776b458f5f086cce24031b3b7c4bdc696f9564b401dcc92c591ec0a4a2767b26ce798ff5d5323517e993feeec
sha512sums = SKIP
pkgname = joplin-appimage