aulos-git

LOW
maintainer robertfoster 0 votes scanned 2026-10-07 00:21:34.957174
View on AUR
Why flagged

The package builds from the project's own Git repository, which is normal for -git AUR packages; the low severity is due to few votes and recent upload, not malicious content.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from the project's own Git repository, which is normal for -git AUR packages; the low severity is due to few votes and recent upload, not malicious content.

PKGBUILD

1# Maintainer: robertfoster
2pkgname=aulos-git
3pkgver=0.1.0.r31.gcc3793e
4pkgrel=1
5pkgdesc='A modern music player for the COSMIC desktop'
6arch=(aarch64 x86_64)
7url=https://github.com/M0Rf30/aulos
8license=(GPL-3.0-only)
9provides=("${pkgname%%-git}")
10conflicts=("${pkgname%%-git}" lyra-git)
11replaces=(lyra-git)
12depends=(
13 cosmic-icon-theme
14 glibc
15 libgcc
16 libgl
17 libxkbcommon
18 wayland
19)
20makedepends=(
21 cargo
22 cmake
23 git
24 just
25 mesa
26 nasm
27)
28optdepends=(
29 'projectm: visualizer presets'
30)
31source=("${pkgname%%-git}::git+${url}.git")
32sha256sums=('SKIP')
33
34pkgver() {
35 cd "${pkgname%%-git}"
36 local _tag
37 if _tag=$(git describe --long --tags 2>/dev/null); then
38 printf '%s' "$_tag" | sed 's/\([^-]*-g\)/r\1/;s/-/./g'
39 else
40 printf '0.1.0.r%s.g%s' "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
41 fi
42}
43
44prepare() {
45 cd "${pkgname%%-git}"
46 cargo fetch --locked
47}
48
49build() {
50 cd "${pkgname%%-git}"
51 # Strip GCC LTO flags — C static libraries (aws-lc-sys, projectm-sys,
52 # libsqlite3-sys) compiled with -flto produce GCC LTO bitcode that
53 # rust-lld (LLVM) cannot link.
54 CFLAGS="${CFLAGS//-flto=auto/}"
55 CXXFLAGS="${CXXFLAGS//-flto=auto/}"
56 just build-release --frozen --features visualizer
57}
58
59package() {
60 cd "${pkgname%%-git}"
61 just rootdir="${pkgdir}" install
62}
63

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 00:21:34 Low 2
2026-10-07 00:04:18 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion