AUR AI Reviewer

Review Results

Version #2597 of firefox-esr-bin · commit e49a57757f5d · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4132

Comment

The change is limited to .SRCINFO metadata and appears to be a routine version bump for the Firefox ESR binary package. No new sources, build steps, install scripts, dependencies, or permissions are introduced here. The only notable issue is that the upstream URL remains HTTP rather than HTTPS, but this is pre-existing and unchanged in this diff. Removing i686 from arch and resetting pkgrel to 0 are normal packaging updates and do not indicate a security problem in this change.

@@ -1,10 +1,9 @@
 pkgbase = firefox-esr-bin
 	pkgdesc = Standalone web browser from mozilla.org - Extended Support Release
-	pkgver = 153.3.0
-	pkgrel = 2
+	pkgver = 153.4.0
+	pkgrel = 0
 	url = http://www.mozilla.org/en-US/firefox/organizations/
 	install = firefox-esr.install
-	arch = i686
 	arch = x86_64
 	license = MPL
 	license = GPL
Risk 0/5 · Safe .SRCINFO
Result #4133

Comment

The change is a routine version bump in .SRCINFO for the Firefox ESR binary package: it updates the upstream release URL, provided version, and the corresponding checksum. The source remains the official Mozilla HTTPS release tarball, with no new sources, scripts, or packaging logic introduced. No signs of persistence, privilege escalation, or build-time code execution are present in this diff hunk.

@@ -14,12 +13,12 @@ pkgbase = firefox-esr-bin
 	depends = dbus-glib
 	depends = nss
 	depends = ffmpeg4.4
-	provides = firefox=153.3.0
-	source = https://ftp.mozilla.org/pub/firefox/releases/153.3.0esr/linux-x86_64/en-US/firefox-153.3.0esr.tar.xz
+	provides = firefox=153.4.0
+	source = https://ftp.mozilla.org/pub/firefox/releases/153.4.0esr/linux-x86_64/en-US/firefox-153.4.0esr.tar.xz
 	source = firefox-esr.desktop
 	source = firefox-esr-safe.desktop
 	source = policies.json
-	sha512sums = 8514dda74bc79228f073e89afdd93e6f69bbb5c38ae3f8ebd4e0e58c1cef20c6a792815534f3fcc371018792541a396949bce396fbbfea31ea2bcebaeef65448
+	sha512sums = ddc705a71bce6d9a8dbed50a99427cb76c2115f94d6d62cfbaa3d37ec009beeb28da293bbbe838ebf663cfe8876ab80d699086717911fc18d7cd8c722c84431b
 	sha512sums = c585f6e8ac7abfc96ad4571940b6f0dcc3f7331a18a518b4fe5d19b45e4c2d96c394524ea5c115c8fdd256c9229ea2fabeb1fc04ca7102f1626fd20728aef47d
 	sha512sums = ab2fa2e08c7a65ac0bfe169a4b579e54b038bddabf838cd3df5ab341bd77be7c101092d0123598944d2174ab3a8fbc70dfbd692b2944016efdb7a69216a74428
 	sha512sums = 5ed67bde39175d4d10d50ba5b12063961e725e94948eadb354c0588b30d3f97d2178b66c1af466a6e7bd208ab694227a1391c4141f88d3da1a1178454eba5308
Risk 0/5 · Safe PKGBUILD
Result #4134

Comment

The change is a routine version bump for a prebuilt Firefox ESR binary package: pkgver/pkgrel and the source checksum were updated, and the package was narrowed to x86_64 only. I do not see any new code execution, network fetches, privilege changes, install-script changes, or suspicious metadata in this diff. The only notable issue is that the package URL remains HTTP rather than HTTPS, but that pre-existed this change and is not introduced here. Overall this diff looks low risk.

@@ -7,18 +7,18 @@
 
 pkgname=firefox-esr-bin
 _pkgname=${pkgname/-bin/}
-pkgver=153.3.0
-pkgrel=2
+pkgver=153.4.0
+pkgrel=0
 pkgdesc='Standalone web browser from mozilla.org - Extended Support Release'
 url='http://www.mozilla.org/en-US/firefox/organizations/'
-arch=('i686' 'x86_64')
+arch=('x86_64')
 depends=('gtk3' 'libxt' 'dbus-glib' 'nss' 'ffmpeg4.4')
 makedepends=()
 provides=(firefox=${pkgver})
 license=('MPL' 'GPL' 'LGPL')
 install=$_pkgname.install
 
-sha512sums=('8514dda74bc79228f073e89afdd93e6f69bbb5c38ae3f8ebd4e0e58c1cef20c6a792815534f3fcc371018792541a396949bce396fbbfea31ea2bcebaeef65448'
+sha512sums=('ddc705a71bce6d9a8dbed50a99427cb76c2115f94d6d62cfbaa3d37ec009beeb28da293bbbe838ebf663cfe8876ab80d699086717911fc18d7cd8c722c84431b'
             'c585f6e8ac7abfc96ad4571940b6f0dcc3f7331a18a518b4fe5d19b45e4c2d96c394524ea5c115c8fdd256c9229ea2fabeb1fc04ca7102f1626fd20728aef47d'
             'ab2fa2e08c7a65ac0bfe169a4b579e54b038bddabf838cd3df5ab341bd77be7c101092d0123598944d2174ab3a8fbc70dfbd692b2944016efdb7a69216a74428'
             '5ed67bde39175d4d10d50ba5b12063961e725e94948eadb354c0588b30d3f97d2178b66c1af466a6e7bd208ab694227a1391c4141f88d3da1a1178454eba5308')