borg2
LOW
maintainer tee
2 votes
scanned 2026-10-08 00:28:03.132797
Why flagged
The pip install occurs in the check() phase within a local venv and installs only the built wheel of the same package for testing, not an external package.
Triggered rules
Low
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install occurs in the check() phase within a local venv and installs only the built wheel of the same package for testing, not an external package.
1 higher static finding superseded - not the current verdict (shown for transparency)
Medium
pip install of an external package
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:78
python-venv/bin/python -m pip install $_pkgname-$pkgver/dist/$_pkgname-$pkgver-*.whl pytest pytest-cov pytest-benchmark msgpack
PKGBUILD
1 offending line(s) highlighted
1
# Contributor: Ketmorco <ketmorco+aur@waynewerner.com>
2
# Contributor: RubenKelevra <cyrond@gmail.com>
3
# Contributor: Lukas Fleischer <lfleischer@archlinux.org>
4
# Contributor: Morten Linderud <foxboron@archlinux.org>
5
# Contributor: Vlad M. <vlad@archlinux.net>
6
# Contributor: Lahfa Samy <'akechishiro-aur' at domain 'lahfa.xyz'>
7
# Contributor: Lauri Niskanen <ape@ape3000.com>
8
# Contributor: tee < teeaur at duck dot com >
9
10
pkgname=borg2
11
_pkgname=borgbackup
12
_borghash_pkgver=0.2.0
13
_borgstore_pkgver=0.7.0
14
pkgver=2.0.0b25
15
pkgrel=1
16
pkgdesc='Deduplicating backup program with compression and authenticated encryption'
17
url='https://borgbackup.org'
18
license=('BSD-3-Clause')
19
arch=('x86_64')
20
depends=(
21
'acl'
22
'lz4'
23
'openssl'
24
'xz'
25
'zstd'
26
'libdeflate'
27
'python-argon2-cffi'
28
"python-borgstore>=${_borgstore_pkgver}"
29
"python-borghash>=${_borghash_pkgver}"
30
'python-jsonargparse'
31
'python-blake3'
32
'python-msgpack'
33
'python-packaging'
34
'python-platformdirs'
35
'python-shtab'
36
'python-yaml'
37
)
38
makedepends=(
39
'git'
40
'cython'
41
'python-build'
42
'python-sphinx'
43
'python-sphinxcontrib-jquery'
44
'python-guzzle-sphinx-theme'
45
'python-installer'
46
'python-pkgconfig'
47
'python-wheel'
48
'python-setuptools'
49
'python-setuptools-scm'
50
)
51
checkdepends=(
52
'python-pytest'
53
'python-pytest-cov'
54
'python-pytest-benchmark'
55
'python-dateutil'
56
)
57
optdepends=(
58
'python-llfuse'
59
'python-pyfuse3'
60
'python-mfusepy'
61
'python-textual'
62
)
63
provides=('borg' 'borgbackup')
64
conflicts=('borg' 'borgbackup')
65
_src='https://github.com/borgbackup/borg'
66
source=("$_src/releases/download/$pkgver/$_pkgname-$pkgver.tar.gz" #{,.asc}
67
)
68
b2sums=('5f275d62ec5dc7734ba4ebfaa2e4c650d21219ee9c2f49a5e46183dc9961b703b38c0e9824f370eb8d6f5e23ed4dfc9784a21caecadb90e8d3a433f6454758c5')
69
validpgpkeys=('6D5BEF9ADD2075805747B70F9F88FB52FAF7B393') # Thomas Waldmann <tw@waldmann-edv.de>
70
71
build() {
72
python -m build --wheel --no-isolation "$_pkgname-$pkgver"
73
}
74
75
check() {
76
python -m venv python-venv --prompt borg
77
source python-venv/bin/activate
78
python-venv/bin/python -m pip install $_pkgname-$pkgver/dist/$_pkgname-$pkgver-*.whl pytest pytest-cov pytest-benchmark msgpack
79
cd "$_pkgname-$pkgver/build/lib.linux-$CARCH-"*/
80
# local skip='not test_non_ascii_acl and not test_with_socket and not test_socket_permissions'
81
# skip+=' and not shell_completions_test and not test_rclone_repo_basics and not test_zsh_completion_syntax'
82
# skip+=' and not test_prune_repository_example_interval and not test_prune_retain_and_expire_oldest'
83
# skip+=' and not test_spinner_colour'
84
local skip='not test_prune_repository_example_interval and not test_prune_retain_and_expire_oldest'
85
env LANG=en_US.UTF-8 PYTHONPATH="$PWD:$PYTHONPATH" "$srcdir/python-venv/bin/python" \
86
-m pytest --cov=borg --benchmark-skip --pyargs borg.testsuite -v -k "$skip"
87
deactivate
88
}
89
90
package() {
91
cd "$_pkgname-$pkgver"
92
python -m installer --compile-bytecode=2 --destdir="$pkgdir" dist/*.whl
93
install -Dm644 docs/man/*.1 -t "$pkgdir/usr/share/man/man1/"
94
install -Dm644 LICENSE -t "$pkgdir/usr/share/licenses/$pkgname/"
95
install -Dm644 README.rst -t "$pkgdir/usr/share/doc/$pkgname/"
96
cd "$pkgdir/usr/bin/"
97
./borg completion bash | install -Dm644 /dev/stdin "$pkgdir"/usr/share/bash-completion/completions/borg
98
./borg completion fish | install -Dm644 /dev/stdin "$pkgdir"/usr/share/fish/vendor_completions.d/borg.fish
99
./borg completion tcsh | install -Dm644 /dev/stdin "$pkgdir"/etc/profile.d/borg.csh
100
./borg completion zsh | install -Dm644 /dev/stdin "$pkgdir"/usr/share/zsh/site-functions/_borg
101
}
102
Changes since previous scan
--- PKGBUILD @ 2026-09-28 00:28+++ PKGBUILD @ 2026-10-08 00:28@@ -9,9 +9,9 @@ pkgname=borg2 _pkgname=borgbackup-_borgstore_pkgver=0.6.1 _borghash_pkgver=0.2.0-pkgver=2.0.0b23+_borgstore_pkgver=0.7.0+pkgver=2.0.0b25 pkgrel=1 pkgdesc='Deduplicating backup program with compression and authenticated encryption' url='https://borgbackup.org'@@ -25,8 +25,8 @@ 'zstd' 'libdeflate' 'python-argon2-cffi'- "python-borgstore=${_borgstore_pkgver}"- "python-borghash=${_borghash_pkgver}"+ "python-borgstore>=${_borgstore_pkgver}"+ "python-borghash>=${_borghash_pkgver}" 'python-jsonargparse' 'python-blake3' 'python-msgpack'@@ -36,13 +36,14 @@ 'python-yaml' ) makedepends=(+ 'git' 'cython'+ 'python-build' 'python-sphinx'+ 'python-sphinxcontrib-jquery' 'python-guzzle-sphinx-theme'- 'git'+ 'python-installer' 'python-pkgconfig'- 'python-build'- 'python-installer' 'python-wheel' 'python-setuptools' 'python-setuptools-scm'@@ -55,34 +56,32 @@ ) optdepends=( 'python-llfuse'+ 'python-pyfuse3' 'python-mfusepy'- 'python-pyfuse3' 'python-textual' ) provides=('borg' 'borgbackup') conflicts=('borg' 'borgbackup') _src='https://github.com/borgbackup/borg' source=("$_src/releases/download/$pkgver/$_pkgname-$pkgver.tar.gz" #{,.asc}-# "${_src}store/releases/download/$_borgstore_pkgver/borgstore-$_borgstore_pkgver.tar.gz" )-b2sums=('0e516a57bc01bc9ce65e74e138492d95b1cd96aab12d09b75cd9b2f6f32a98eb1793480953d8b68a8aa242c8762f12e80e65d1737d8b5d33c7f5b333ef3f3e97')+b2sums=('5f275d62ec5dc7734ba4ebfaa2e4c650d21219ee9c2f49a5e46183dc9961b703b38c0e9824f370eb8d6f5e23ed4dfc9784a21caecadb90e8d3a433f6454758c5') validpgpkeys=('6D5BEF9ADD2075805747B70F9F88FB52FAF7B393') # Thomas Waldmann <tw@waldmann-edv.de> build() {- #python -m build --wheel --no-isolation "borgstore-$_borgstore_pkgver" python -m build --wheel --no-isolation "$_pkgname-$pkgver" } check() { python -m venv python-venv --prompt borg source python-venv/bin/activate- #python-venv/bin/python -m pip install borgstore-${_borgstore_pkgver}/dist/borgstore-${_borgstore_pkgver}-py3-none-any.whl python-venv/bin/python -m pip install $_pkgname-$pkgver/dist/$_pkgname-$pkgver-*.whl pytest pytest-cov pytest-benchmark msgpack cd "$_pkgname-$pkgver/build/lib.linux-$CARCH-"*/- local skip='not test_non_ascii_acl and not test_with_socket and not test_socket_permissions'- skip+=' and not shell_completions_test and not test_rclone_repo_basics and not test_zsh_completion_syntax'- skip+=' and not test_prune_repository_example_interval and not test_prune_retain_and_expire_oldest'- skip+=' and not test_spinner_colour'+# local skip='not test_non_ascii_acl and not test_with_socket and not test_socket_permissions'+# skip+=' and not shell_completions_test and not test_rclone_repo_basics and not test_zsh_completion_syntax'+# skip+=' and not test_prune_repository_example_interval and not test_prune_retain_and_expire_oldest'+# skip+=' and not test_spinner_colour'+ local skip='not test_prune_repository_example_interval and not test_prune_retain_and_expire_oldest' env LANG=en_US.UTF-8 PYTHONPATH="$PWD:$PYTHONPATH" "$srcdir/python-venv/bin/python" \ -m pytest --cov=borg --benchmark-skip --pyargs borg.testsuite -v -k "$skip" deactivate@@ -90,15 +89,14 @@ package() { cd "$_pkgname-$pkgver"- python -m installer --compile-bytecode=2 --destdir="$pkgdir" dist/*.whl install -Dm644 docs/man/*.1 -t "$pkgdir/usr/share/man/man1/" install -Dm644 LICENSE -t "$pkgdir/usr/share/licenses/$pkgname/" install -Dm644 README.rst -t "$pkgdir/usr/share/doc/$pkgname/" cd "$pkgdir/usr/bin/"- ./borg completion bash 2>/dev/null | install -Dm644 /dev/stdin "$pkgdir/usr/share/bash-completion/completions/borg"- ./borg completion fish 2>/dev/null | install -Dm644 /dev/stdin "$pkgdir/usr/share/fish/vendor_completions.d/borg.fish"- ./borg completion tcsh 2>/dev/null | install -Dm644 /dev/stdin "$pkgdir/etc/profile.d/borg.tcsh"- ./borg completion zsh 2>/dev/null | install -Dm644 /dev/stdin "$pkgdir/usr/share/zsh/site-functions/_borg"+ ./borg completion bash | install -Dm644 /dev/stdin "$pkgdir"/usr/share/bash-completion/completions/borg+ ./borg completion fish | install -Dm644 /dev/stdin "$pkgdir"/usr/share/fish/vendor_completions.d/borg.fish+ ./borg completion tcsh | install -Dm644 /dev/stdin "$pkgdir"/etc/profile.d/borg.csh+ ./borg completion zsh | install -Dm644 /dev/stdin "$pkgdir"/usr/share/zsh/site-functions/_borg } Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-08 00:28:03 | Low | 2 |
| 2026-10-07 00:21:34 | Low | 2 |
| 2026-10-06 00:13:36 | Low | 2 |
| 2026-10-05 00:08:03 | Low | 2 |
| 2026-10-04 00:18:08 | Low | 2 |
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 07:20:27 | Medium | 1 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |