badclip

LOW
maintainer imjiaoyuan 0 votes scanned 2026-10-08 16:09:18.783063
View on AUR
Why flagged

The package builds from a pinned commit of the upstream GitHub repository, which is normal AUR practice; the low severity is due to few votes and recent upload, not malicious content.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from a pinned commit of the upstream GitHub repository, which is normal AUR practice; the low severity is due to few votes and recent upload, not malicious content.

PKGBUILD

1# Maintainer: imjiaoyuan <imjiaoyuan@gmail.com>
2# Upstream tags nothing, so pkgver is the pinned commit's date and _tag carries
3# the commit itself. Cargo.toml declares `license = "MIT"` even though the tree
4# ships no LICENSE file, so the MIT text is written out here with the author's
5# attribution (upstream should carry a real LICENSE file).
6
7pkgname=badclip
8_tag=b1825a9053c1729936fcf8537e234d91fcb123f0
9pkgver=20261003
10pkgrel=1
11pkgdesc="Extract breakends and structural-variant signals from long-read alignments"
12arch=('x86_64' 'aarch64')
13url="https://github.com/lh3/badclip"
14license=('MIT')
15depends=('glibc' 'gcc-libs')
16makedepends=('rust')
17source=("$pkgname-$pkgver.tar.gz::${url}/archive/${_tag}.tar.gz")
18sha256sums=('33e386fa401c1ddb3ffe82ea31009f48049c326471b1850a321b917e255cffbc')
19
20build() {
21 cd "$srcdir/$pkgname-$_tag"
22 # Arch's -flto=auto breaks rustc's lto=thin link for bundled C crates.
23 export CFLAGS="${CFLAGS//-flto=auto/}"
24 export CXXFLAGS="${CXXFLAGS//-flto=auto/}"
25 export LDFLAGS="${LDFLAGS//-flto=auto/}"
26 cargo build --release --locked
27}
28
29package() {
30 cd "$srcdir/$pkgname-$_tag"
31 install -Dm755 "target/release/$pkgname" "$pkgdir/usr/bin/$pkgname"
32 cat > LICENSE <<'EOF'
33MIT License
34
35Copyright (c) 2026 Heng Li
36
37Permission is hereby granted, free of charge, to any person obtaining a copy
38of this software and associated documentation files (the "Software"), to deal
39in the Software without restriction, including without limitation the rights
40to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
41copies of the Software, and to permit persons to whom the Software is
42furnished to do so, subject to the following conditions:
43
44The above copyright notice and this permission notice shall be included in all
45copies or substantial portions of the Software.
46
47THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
48IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
49FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
50AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
51LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
52OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
53SOFTWARE.
54EOF
55 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
56}
57

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 16:09:18 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion