cantarell-static-fonts
The pip install is used to install build dependencies (pip-tools and requirements from the project's own requirements.in and requirements.txt) during the build process, which is a normal part of building the project from source; the packages are not externally injected and are tied to the verified source tarball.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install is used to install build dependencies (pip-tools and requirements from the project's own requirements.in and requirements.txt) during the build process, which is a normal part of building the project from source; the packages are not externally injected and are tied to the verified source tarball.
1 higher static finding superseded - not the current verdict (shown for transparency)
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:28
pip install pip-tools -
PKGBUILD:30
pip install -r $_pkgname-$pkgver/requirements.txt
PKGBUILD
2 offending line(s) highlighted# Maintainer: Jan Sonntag <jaso35 at gmail dot com>
pkgname=cantarell-static-fonts
_pkgname=cantarell-fonts
pkgver=0.303.1
pkgrel=3
pkgdesc="Humanist sans serif font - static fonts"
url="https://gitlab.gnome.org/GNOME/cantarell-fonts"
arch=(any)
provides=(cantarell-fonts)
conflicts=(cantarell-fonts)
license=(custom:SIL)
makedepends=(meson appstream-glib python)
source=("https://download.gnome.org/sources/${_pkgname}/${pkgver:0:5}/${_pkgname}-$pkgver.tar.xz"
"only_remove_overlaps_with_pathops_if_available.patch")
sha256sums=('f9463a0659c63e57e381fdd753cf1929225395c5b49135989424761830530411'
'5ebb937d0583773ec383537db8f5d3891f9c8fb7d1b5a9d8f1d16219e17858c8')
prepare() {
cd "$_pkgname-$pkgver"
patch --forward --strip=1 --input="${srcdir}/only_remove_overlaps_with_pathops_if_available.patch"
}
build() {
python -m venv venv
source venv/bin/activate
pip install pip-tools
pip-compile --upgrade $_pkgname-$pkgver/requirements.in
pip install -r $_pkgname-$pkgver/requirements.txt
arch-meson $_pkgname-$pkgver build -D buildstatics=true -D buildvf=false
meson compile -C build
}
package() {
meson install -C build --destdir "$pkgdir"
install -Dt "$pkgdir/usr/share/licenses/$pkgname" -m644 $_pkgname-$pkgver/COPYING
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |