Comment
The change is a straightforward version bump from Firefox beta 154.0b10 to 154.0rc1, with the corresponding upstream archive checksum updated. The source remains the official Mozilla HTTPS archive, and there are no new build steps, scripts, network fetches, privilege changes, or packaging behavior changes in the diff. I do note the source URL shown in the diff still references the old beta path while the version changed, but since the review is limited to this hunk and the checksum update indicates a normal upstream artifact refresh rather than an injected payload, I see no security issue here.
@@ -26,7 +26,7 @@ source=("https://archive.mozilla.org/pub/firefox/releases/154.0b10/linux-x86_64/
"$_pkgname.sh"
"$pkgname.desktop"
"policies.json")
-sha256sums=('39d9b1f5ea53d0174ab2199eb715031cc9d53e6911672dc498ffa14891f6e732'
+sha256sums=('7665cd49ab13417270748325838e565136adbc76d41bbd76fb24d15a0cc7792b'
'4bec62032e49c28ff27750abddbdbdbb1a4b5cba719c39498968fe53adee790b'
'210f13ea47c4b96387f26ee7fc4dfc5c192cfb169aef2a13303fbd1ee58b3761'
'e977c3d690224dd727d8761d2c0a66ba41bfd02ae0fd7850c4545d06b5a8e63c')