AUR AI Reviewer

Review Results

Version #2666 of joplin · commit 2733ea05c152 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4382

Comment

The only change in this .SRCINFO diff is a version bump from 3.7.18 to 3.7.21. No source URLs, checksums, build steps, install scripts, permissions, or package metadata were altered in the provided hunk, so there is no new security concern visible here. Based on this diff alone, the change appears routine and low risk.

@@ -1,6 +1,6 @@
 pkgbase = joplin
 	pkgdesc = A note taking and to-do application with synchronization capabilities
-	pkgver = 3.7.18
+	pkgver = 3.7.21
 	pkgrel = 1
 	url = https://joplinapp.org/
 	arch = x86_64
Risk 0/5 · Safe .SRCINFO
Result #4383

Comment

The change is a straightforward version bump in .SRCINFO from Joplin 3.7.18 to 3.7.21, with corresponding checksum updates for the same GitHub release tarball and the existing auxiliary sources. The source remains HTTPS on the official upstream repository, there are no new build steps, scripts, or integrity red flags introduced by this diff, and no evidence of typosquatting, floating VCS refs, or added network/execution behavior.

@@ -19,10 +19,10 @@ pkgbase = joplin
 	optdepends = libappindicator-gtk3: for tray icon
 	source = joplin-desktop.sh
 	source = joplin-desktop.desktop
-	source = joplin-3.7.18.tar.gz::https://github.com/laurent22/joplin/archive/v3.7.18.tar.gz
-	sha256sums = 9223cc816f8175ddaf8839f9357d2bd1c4831692504927c98d8e1eefa7df796e
-	sha256sums = f485c089904d91750d137d4413297676446e0068892cb08e20bee928bcac516c
-	sha256sums = 60eb34872a61efce325034ab1a052a0d37f9f0028b037d5482b1e649d8d63c4f
+	source = joplin-3.7.21.tar.gz::https://github.com/laurent22/joplin/archive/v3.7.21.tar.gz
+	sha256sums = 3f87fe0167806c86495fab78483cce83d60262bc2289e5ff24a9a9039e8454b2
+	sha256sums = fb9a5185e3b523a5f52b0eeec6def781782ad0e6b64e5db13300396b835a55b4
+	sha256sums = d868a2f9a48937c514b6b39486e88f473b4477085035f75d22542800c1fdd083
 
 pkgname = joplin
 	pkgdesc = A note taking and to-do application with synchronization capabilities - CLI App
Risk 1/5 · Low PKGBUILD
Result #4384

Comment

The change is a routine version bump plus checksum refresh, but it also adds two build-time source edits. One hardcodes the desktop executable path to /usr/bin/joplin-desktop, and the other strips a specific app.asar argument when launching a secondary instance. These are targeted functional changes for packaging on system Electron and do not introduce network access, privilege escalation, persistence, or other obvious supply-chain red flags. The modified sed regex broadens matching from \w+ to [^"]+, which is still confined to rewriting local package.json references during build. Overall this looks low risk.

@@ -8,7 +8,7 @@
 pkgbase=joplin
 pkgname=('joplin' 'joplin-desktop')
 pkgdesc="A note taking and to-do application with synchronization capabilities"
-pkgver=3.7.18
+pkgver=3.7.21
 groups=('joplin')
 pkgrel=1
 _electronVersion=42
Risk 0/5 · Safe PKGBUILD
Result #4385

Comment

The change is a routine upstream version bump plus checksum refresh, with two small build-time source edits to make Joplin work with the system Electron package. I do not see supply-chain red flags: sources remain HTTPS from the official GitHub release archive, no new external downloads or unpinned VCS sources were introduced, and the added sed patches only adjust local source code during build. The modified lines do not add persistence, privilege escalation, or network activity in package()/.install. Overall this looks low risk.

@@ -23,9 +23,9 @@ source=(
     "joplin-desktop.desktop"
     "joplin-${pkgver}.tar.gz::https://github.com/laurent22/joplin/archive/v${pkgver}.tar.gz"
 )
-sha256sums=('9223cc816f8175ddaf8839f9357d2bd1c4831692504927c98d8e1eefa7df796e'
-            'f485c089904d91750d137d4413297676446e0068892cb08e20bee928bcac516c'
-            '60eb34872a61efce325034ab1a052a0d37f9f0028b037d5482b1e649d8d63c4f')
+sha256sums=('3f87fe0167806c86495fab78483cce83d60262bc2289e5ff24a9a9039e8454b2'
+            'fb9a5185e3b523a5f52b0eeec6def781782ad0e6b64e5db13300396b835a55b4'
+            'd868a2f9a48937c514b6b39486e88f473b4477085035f75d22542800c1fdd083')
 
 _setup_env() {
     export YARN_CACHE_FOLDER="${srcdir}/yarn-cache"
Risk 1/5 · Low PKGBUILD
Result #4386

Comment

The change is low risk overall. It only updates the package version/checksums and adjusts build-time patches for the desktop app. The new sed edits are narrowly scoped to source files in the build tree: one hardcodes the system electron executable path for the secondary-instance feature, and the other strips a specific app.asar argument from process start flags. There is no evidence of network fetches, privilege escalation, persistence, or installation outside the package build directory. The regex broadening from \w+ to [^"]+ is a build helper change to support package names with non-word characters and does not introduce code execution or integrity issues.

@@ -53,16 +53,20 @@ build() {
     rm -r packages/{app-mobile,app-clipper,server,doc-builder}
     # Fix: Build error due to removal of app-mobile
     sed -i '/app-mobile\//d' packages/tools/gulp/tasks/buildScriptIndexes.js
-
     # Fix: joplin-plugin-freehand-drawing complains "not in a git directory"
     git init
+    # Fix: "Open secondary app instance" not working with system electron
+    sed -i "s#bridge().electronApp().electronApp().getPath('exe')#'/usr/bin/joplin-desktop'#" \
+        packages/app-desktop/bridge.ts
+    sed -i '/const nextArg/a if (arg === "/usr/lib/joplin-desktop/app.asar") { argv.splice(0, 2); continue; }' \
+        packages/lib/utils/processStartFlags.ts
 
     corepack install
     npx yarn install
 
     # Replace npm dependencies with local ones
     cd "packages"
-    sed -i -E 's_"@joplin/(\w+)": .*_"@joplin/\1": "file://'$PWD'/\1",_g' */package.json
+    sed -i -E 's_"@joplin/([^"]+)": .*_"@joplin/\1": "file://'$PWD'/\1",_g' */package.json
 
     # Pack the app-cli package
     cd "${srcdir}/joplin-${pkgver}/packages/app-cli"
Risk 0/5 · Safe joplin-desktop.desktop
Result #4387

Comment

This is a low-risk desktop-entry metadata change only. It updates StartupWMClass from the upstream Electron class name to the AppImageKit class name, which affects window matching/taskbar grouping but does not introduce code execution, privilege changes, network access, or packaging integrity issues. No suspicious install-time behavior is present in the reviewed hunk.

@@ -4,7 +4,7 @@ Comment=Joplin for Desktop
 Exec=/usr/bin/joplin-desktop
 Terminal=false
 Icon=joplin-desktop
-StartupWMClass=@joplin/app-desktop
+StartupWMClass=appimagekit-joplin
 Type=Application
 Categories=Office;
 MimeType=x-scheme-handler/joplin;
Risk 0/5 · Safe joplin-desktop.sh
Result #4388

Comment

The change is a shell-wrapper refactor that adds support for user-controlled Electron flags from ~/.config and preserves existing environment exports. I do not see any network access, privilege escalation, persistence, or writes outside the package scope. The main security consideration is that the wrapper now reads arbitrary lines from a per-user config file and passes them as Electron flags, which is expected behavior for a desktop launcher and is limited to the invoking user. No suspicious commands or hidden execution paths are introduced.

@@ -1,5 +1,31 @@
 #!/bin/bash
+# This script is forked from Arch-stock /usr/bin/electron*
 
-export ELECTRON_IS_DEV=0
-cd /usr/lib/joplin-desktop || exit 1
-exec electron@electronversion@ /usr/lib/joplin-desktop/app.asar "$@"
+set -euo pipefail
+
+name=electron@electronversion@
+flags_file="${XDG_CONFIG_HOME:-$HOME/.config}/${name}-flags.conf"
+fallback_file="${XDG_CONFIG_HOME:-$HOME/.config}/electron-flags.conf"
+
+lines=()
+if [[ -f "${flags_file}" ]]; then
+    mapfile -t lines < "${flags_file}"
+elif [[ -f "${fallback_file}" ]]; then
+    mapfile -t lines < "${fallback_file}"
+fi
+
+flags=()
+for line in "${lines[@]}"; do
+    if [[ ! "${line}" =~ ^[[:space:]]*#.* ]] && [[ -n "${line}" ]]; then
+        flags+=("${line}")
+    fi
+done
+
+: ${ELECTRON_IS_DEV:=0}
+export ELECTRON_IS_DEV
+: ${ELECTRON_FORCE_IS_PACKAGED:=true}
+export ELECTRON_FORCE_IS_PACKAGED
+
+cd /usr/lib/joplin-desktop
+# Pass electron flags before asar path, and Joplin flags after it.
+exec /usr/lib/${name}/electron "${flags[@]}" /usr/lib/joplin-desktop/app.asar -- "$@"