cantarell-static-fonts
maintainer orphaned
· 2 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The pip install is used to install build dependencies (pip-tools and requirements from the project's own requirements.in and requirements.txt) during the build process, which is a normal part of building the project from source; the packages are not externally injected and are tied to the verified source tarball.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install is used to install build dependencies (pip-tools and requirements from the project's own requirements.in and requirements.txt) during the build process, which is a normal part of building the project from source; the packages are not externally injected and are tied to the verified source tarball.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
pip install of an external package
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:28
pip install pip-tools -
PKGBUILD:30
pip install -r $_pkgname-$pkgver/requirements.txt
PKGBUILD
2 offending line(s) highlighted
1
# Maintainer: Jan Sonntag <jaso35 at gmail dot com>
2
3
pkgname=cantarell-static-fonts
4
_pkgname=cantarell-fonts
5
pkgver=0.303.1
6
pkgrel=3
7
pkgdesc="Humanist sans serif font - static fonts"
8
url="https://gitlab.gnome.org/GNOME/cantarell-fonts"
9
arch=(any)
10
provides=(cantarell-fonts)
11
conflicts=(cantarell-fonts)
12
license=(custom:SIL)
13
makedepends=(meson appstream-glib python)
14
source=("https://download.gnome.org/sources/${_pkgname}/${pkgver:0:5}/${_pkgname}-$pkgver.tar.xz"
15
"only_remove_overlaps_with_pathops_if_available.patch")
16
sha256sums=('f9463a0659c63e57e381fdd753cf1929225395c5b49135989424761830530411'
17
'5ebb937d0583773ec383537db8f5d3891f9c8fb7d1b5a9d8f1d16219e17858c8')
18
19
prepare() {
20
cd "$_pkgname-$pkgver"
21
patch --forward --strip=1 --input="${srcdir}/only_remove_overlaps_with_pathops_if_available.patch"
22
23
}
24
25
build() {
26
python -m venv venv
27
source venv/bin/activate
28
pip install pip-tools
29
pip-compile --upgrade $_pkgname-$pkgver/requirements.in
30
pip install -r $_pkgname-$pkgver/requirements.txt
31
arch-meson $_pkgname-$pkgver build -D buildstatics=true -D buildvf=false
32
meson compile -C build
33
}
34
35
package() {
36
meson install -C build --destdir "$pkgdir"
37
install -Dt "$pkgdir/usr/share/licenses/$pkgname" -m644 $_pkgname-$pkgver/COPYING
38
}
39
40
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |