amifuse
maintainer chandlerkc
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The pip install is used to install the project's own editable packages from the locally checked-out git source, not external untrusted packages; this is a normal part of building the project and poses no supply-chain risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The pip install is used to install the project's own editable packages from the locally checked-out git source, not external untrusted packages; this is a normal part of building the project and poses no supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
pip install of an external package
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:21
pip install -e './amitools[vamos]'
PKGBUILD
1 offending line(s) highlighted
1
# Creator: Stefan Reinauer <reinauer@google.com>
2
# Maintainer: Chandler Klüser <chandler.kluser@gmail.com>
3
pkgname=amifuse
4
pkgver=0.5.0
5
pkgrel=0
6
pkgdesc="Native AMIGA filesystems on Linux with FUSE"
7
arch=('x86_64')
8
url="https://github.com/reinauer/amifuse"
9
depends=('fuse' 'python' 'python-virtualenv')
10
makedepends=('git')
11
provides=("amifuse=${pkgver}")
12
source=('git+https://github.com/reinauer/amifuse.git#commit=30b5429843ac23c61076c61f15597ed8bdd3042f')
13
sha256sums=('13bf0b8e5aa8976fc3772402f6b35adfe70c42677329139b750221c5a7c76431')
14
15
build() {
16
cd ${pkgname}
17
git config submodule.amitools.url https://github.com/cnvogelg/amitools.git
18
git submodule update --init --recursive
19
python -m venv .venv
20
source .venv/bin/activate
21
pip install -e './amitools[vamos]'
22
pip install -e .
23
}
24
25
package() {
26
cd ${pkgname}
27
source .venv/bin/activate
28
29
# Install the generated console scripts
30
install -Dm755 .venv/bin/amifuse "${pkgdir}/usr/bin/amifuse"
31
install -Dm755 .venv/bin/rdb-inspect "${pkgdir}/usr/bin/rdb-inspect"
32
install -Dm755 .venv/bin/driver-info "${pkgdir}/usr/bin/driver-info"
33
34
# Optional: Install documentation
35
install -Dm644 README.md "${pkgdir}/usr/share/doc/amifuse/README.md"
36
cp -r Docs "${pkgdir}/usr/share/doc/amifuse/"
37
}
38
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |