bedstead-fonts-powerline

maintainer Indeo · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads font files and a patcher script from the project's official domain; building and patching fonts locally is normal AUR packaging, and the source host, while not whitelisted, is plausibly legitimate and specific to the project.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads font files and a patcher script from the project's official domain; building and patching fonts locally is normal AUR packaging, and the source host, while not whitelisted, is plausibly legitimate and specific to the project.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 "https://bjh21.me.uk/bedstead/bedstead.otf"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Alex <indigo@protonmail.ch>
2
3pkgname=bedstead-fonts-powerline
4pkgver=1.0
5pkgrel=5
6pkgdesc="Bedstead is a family of outline fonts based on the characters produced by the Mullard SAA5050 series of Teletext Character Generators. Patched for powerline"
7url="https://bjh21.me.uk/bedstead/"
8arch=(any)
9license=(custom)
10makedepends=('python>=3.0.0'
11 'fontforge')
12source=("patcher::git+https://github.com/powerline/fontpatcher"
13 "https://bjh21.me.uk/bedstead/bedstead.otf"
14 "https://bjh21.me.uk/bedstead/bedstead-extended.otf"
15 "https://bjh21.me.uk/bedstead/bedstead-semicondensed.otf"
16 "https://bjh21.me.uk/bedstead/bedstead-ultracondensed.otf")
17
18build() {
19 sed -i 's/python2/python3/g' $srcdir/patcher/scripts/powerline-fontpatcher
20 cd $srcdir
21 for font in ${srcdir}/*.otf
22 do
23 ./patcher/scripts/powerline-fontpatcher $font
24 done
25}
26
27package() {
28 install -d "$pkgdir/usr/share/fonts/${pkgname%-fonts}"
29 install -t "$pkgdir/usr/share/fonts/${pkgname%-fonts}" -m644 *Powerline.otf
30}
31sha256sums=('SKIP'
32 '414aa3746e629d4efe17fe4c6400cf109214e082e51f8254c70e9d070e21f56d'
33 'a3a21dfbe3338b2fa4b31b2dd65dd8ff4c54bd94811b7c79fe799fb43870371f'
34 '01a2f3d4956f4a36bc5fa636fc6595a636007565fabb9705341ed05123f0597e'
35 '236cd7c7a28a6776d9a2e0873527f41d21fd576a83b81bca4a757a87110b932e')
36

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion