Risk 2/5 · Moderate
PKGBUILD
Result #4412
Comment
The change adds a new build-time patch source fetched directly from a GitHub pull request URL and applies it in prepare(). This is not inherently malicious, but it does expand the trust boundary beyond the upstream release tarball to an unpinned, mutable PR artifact. I could not inspect the patch contents from the repository checkout because the patch file is not present locally, so there is some integrity risk in relying on a remote PR patch rather than an upstream release/tagged commit or a vendored patch in-tree. No obvious shell execution, privilege escalation, or install-script persistence is introduced in the PKGBUILD itself.
@@ -45,8 +45,17 @@ optdepends=(
'xxd: required for SteamTinkerLaunch'
'yad: required for SteamTinkerLaunch'
)
-source=("$pkgname-$pkgver.tar.gz::https://github.com/DavidoTek/ProtonUp-Qt/archive/refs/tags/v$pkgver.tar.gz")
-sha256sums=('7028c0f3451fcb69f384ba0687b58a973b35fab2b0a64d5435eb1f782f09ea08')
+source=("$pkgname-$pkgver.tar.gz::https://github.com/DavidoTek/ProtonUp-Qt/archive/refs/tags/v$pkgver.tar.gz"
+ 'https://github.com/DavidoTek/ProtonUp-Qt/pull/647.patch')
+sha256sums=('7028c0f3451fcb69f384ba0687b58a973b35fab2b0a64d5435eb1f782f09ea08'
+ '9cbbea6c9e600ebe2ecb85ec4ebf5d00a48fdaf3d8c2fc88288d26e9a206280d')
+
+prepare() {
+ cd "ProtonUp-Qt-$pkgver"
+
+ # Support proton-wineland
+ patch -Np1 -i ../647.patch
+}
build() {
cd "ProtonUp-Qt-$pkgver"