chemtool-proper
maintainer ConnorBehan
· 3 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a tarball from a university-hosted personal page, which is not on a standard code forge but plausibly the original developer's official site; it is a standard source tarball for a known software, built locally with patches, and no untrusted executables or remote code execution occur.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from a university-hosted personal page, which is not on a standard code forge but plausibly the original developer's official site; it is a standard source tarball for a known software, built locally with patches, and no untrusted executables or remote code execution occur.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz
PKGBUILD
1 offending line(s) highlighted
1
# Contributor: Connor Behan <connor.behan@gmail.com>
2
3
pkgname=chemtool-proper
4
pkgver=1.6.14
5
pkgrel=3
6
pkgdesc="Chemtool ported to Gtk3 with assistance from Codex"
7
arch=(i686 x86_64)
8
license=('GPL2')
9
url="http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool.html"
10
depends=('gtk3')
11
replaces=('chemtool')
12
provides=('chemtool')
13
options=(!libtool)
14
source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz
15
0001-Add-GTK3-compatibility-drawing-layer.patch
16
0002-Port-chemtool-sources-to-GTK3.patch
17
gtk3_build_system.patch
18
chemtool.desktop)
19
20
prepare() {
21
cd "$srcdir"/chemtool-$pkgver
22
patch -Np1 -i ../gtk3_build_system.patch
23
patch -Np2 -i ../0001-Add-GTK3-compatibility-drawing-layer.patch
24
patch -Np2 -i ../0002-Port-chemtool-sources-to-GTK3.patch
25
./autogen.sh
26
}
27
28
build() {
29
cd "$srcdir"/chemtool-$pkgver
30
CFLAGS+=' -fcommon' # https://wiki.gentoo.org/wiki/Gcc_10_porting_notes/fno_common
31
./configure --prefix=/usr --mandir=/usr/share/man
32
make
33
}
34
35
package() {
36
cd "$srcdir"/chemtool-$pkgver
37
make DESTDIR="$pkgdir" install
38
install -D -m644 gnome/chemtool.png "$pkgdir"/usr/share/pixmaps/chemtool.png
39
install -D -m644 "$srcdir"/chemtool.desktop "$pkgdir"/usr/share/applications/chemtool.desktop
40
}
41
42
sha256sums=('86161a0461386b334a5ffb17cdf094a491941884678272f45749813514ddafcb'
43
'b7278a7256ef5c2cfc6ede8e9d577cae662d9e107a3d29b152122f499ffa68b9'
44
'a81ffc0a44b4c856a2633eefcb9d0aced2695c5de0f7bbcb99ba952665a9a8ff'
45
'5cfb774056a88c6e7dcd52233c740a27e592208292e9471e565b86832ec99e16'
46
'9c35347faa7aa664c012f0d66fffbd469c4f2f3f8f24e5dd0cd42d554e9c5ac7')
47
Changes since previous scan
--- PKGBUILD @ 2026-07-22 00:29+++ PKGBUILD @ 2026-08-03 00:08@@ -2,20 +2,31 @@ pkgname=chemtool-proper pkgver=1.6.14-pkgrel=2-pkgdesc="Chemtool without the stupid right justified help menu"+pkgrel=3+pkgdesc="Chemtool ported to Gtk3 with assistance from Codex" arch=(i686 x86_64) license=('GPL2') url="http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool.html"-depends=('gtk2')+depends=('gtk3') replaces=('chemtool') provides=('chemtool') options=(!libtool)-source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz chemtool.desktop)+source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz+ 0001-Add-GTK3-compatibility-drawing-layer.patch+ 0002-Port-chemtool-sources-to-GTK3.patch+ gtk3_build_system.patch+ chemtool.desktop)++prepare() {+ cd "$srcdir"/chemtool-$pkgver+ patch -Np1 -i ../gtk3_build_system.patch+ patch -Np2 -i ../0001-Add-GTK3-compatibility-drawing-layer.patch+ patch -Np2 -i ../0002-Port-chemtool-sources-to-GTK3.patch+ ./autogen.sh+} build() { cd "$srcdir"/chemtool-$pkgver- sed -i -e 's/.*right_justify.*//g' main.c CFLAGS+=' -fcommon' # https://wiki.gentoo.org/wiki/Gcc_10_porting_notes/fno_common ./configure --prefix=/usr --mandir=/usr/share/man make@@ -28,6 +39,9 @@ install -D -m644 "$srcdir"/chemtool.desktop "$pkgdir"/usr/share/applications/chemtool.desktop } -md5sums=('3a97680f0abe1327af1f0072551a68e2'- '8cbb6f7021bd5aaa6f6a31fc4d95a06e')+sha256sums=('86161a0461386b334a5ffb17cdf094a491941884678272f45749813514ddafcb'+ 'b7278a7256ef5c2cfc6ede8e9d577cae662d9e107a3d29b152122f499ffa68b9'+ 'a81ffc0a44b4c856a2633eefcb9d0aced2695c5de0f7bbcb99ba952665a9a8ff'+ '5cfb774056a88c6e7dcd52233c740a27e592208292e9471e565b86832ec99e16'+ '9c35347faa7aa664c012f0d66fffbd469c4f2f3f8f24e5dd0cd42d554e9c5ac7') Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 05:19:42 | MEDIUM | 1 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |