blackpenguin
The source is a tarball from a historical Linux software archive (ibiblio.org), which is a legitimate but non-whitelisted host; the package builds from source and installs only game binaries and data, with no evidence of malicious behavior or unverifiable prebuilt executables.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from a historical Linux software archive (ibiblio.org), which is a legitimate but non-whitelisted host; the package builds from source and installs only game binaries and data, with no evidence of malicious behavior or unverifiable prebuilt executables.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
source=("http://www.ibiblio.org/pub/linux/games/arcade/${pkgname}-${pkgver}.tar.gz"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Ian D. Scott <ian@iandouglasscott.com>
# old maintainer: Jens Staal <staal1978@gmail.com>
# old maintainer: Anton Bazhenov <anton.bazhenov at gmail>
pkgname=blackpenguin
pkgver=0.2
pkgrel=4
pkgdesc="An arcade style jump-on-cubes game with Penguin and Evil Window"
arch=('i686' 'x86_64')
url="http://www.ibiblio.org/pub/linux/games/arcade/"
license=('GPL')
depends=('libxext' 'qt5-base')
#in order to go more modern, more invasive changes are needed
#qt5 does not provide the qt3 compat headers and libs
source=("http://www.ibiblio.org/pub/linux/games/arcade/${pkgname}-${pkgver}.tar.gz"
"${pkgname}.patch"
"${pkgname}.png"
"${pkgname}.desktop"
"qt2to4.patch"
"blackpenguin-qt5.patch")
md5sums=('91ac8ac0f5588122c469e3f65b98c3df'
'f3ca77928e512e263fbf9e769d614260'
'9204e564d47ea7ce9592232e2bd31c92'
'55d2533c522dae44e9ac739a6fb287c0'
'5705ea4929b6eea8b4d39a4052ff5743'
'e9f73a47936e2eaeafe1f492cac53427')
build() {
cd "${srcdir}/${pkgname}-${pkgver}/src"
rm blackpenguin #ensure that a new binary is made
patch -Np2 -i ../../${pkgname}.patch
patch -Np2 -i ../../qt2to4.patch
mv appwindow.cpp{.alt,}
patch -Np2 -i ../../blackpenguin-qt5.patch
qmake-qt5 -makefile
make
}
package() {
cd "${srcdir}/${pkgname}-${pkgver}"
# Install game files
install -Dm755 src/${pkgname} "${pkgdir}/usr/bin/${pkgname}"
# Install a desktop entry
install -Dm644 ../${pkgname}.png "${pkgdir}/usr/share/pixmaps/${pkgname}.png"
install -Dm644 ../${pkgname}.desktop "${pkgdir}/usr/share/applications/${pkgname}.desktop"
# Install a readme file
install -Dm644 doc/README "${pkgdir}/usr/share/${pkgname}/README"
}
# vim:set ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |