(Revised due to accidental reply to an old thread) Package:https://aur.archlinux.org/packages/plasma6-applet-quicklaunch
Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/ Problematic Upstream File: https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml The "security-audit.yml" which will be executed in actions runner is actually extracting API keys and cloud creds and upload them to an external server. Although I believe that building this package using PKGBUILD harmless, the package upstream cannot be trusted anymore. Also note that the package submitter/maintainer may not be affiliated with the upstream author.
