chemtool-proper

LOW
maintainer ConnorBehan 3 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a tarball from a university-hosted personal page, which is not on a standard code forge but plausibly the original developer's official site; it is a standard source tarball for a known software, built locally with patches, and no untrusted executables or remote code execution occur.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from a university-hosted personal page, which is not on a standard code forge but plausibly the original developer's official site; it is a standard source tarball for a known software, built locally with patches, and no untrusted executables or remote code execution occur.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz

PKGBUILD

1 offending line(s) highlighted
1# Contributor: Connor Behan <connor.behan@gmail.com>
2
3pkgname=chemtool-proper
4pkgver=1.6.14
5pkgrel=3
6pkgdesc="Chemtool ported to Gtk3 with assistance from Codex"
7arch=(i686 x86_64)
8license=('GPL2')
9url="http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool.html"
10depends=('gtk3')
11replaces=('chemtool')
12provides=('chemtool')
13options=(!libtool)
14source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz
15 0001-Add-GTK3-compatibility-drawing-layer.patch
16 0002-Port-chemtool-sources-to-GTK3.patch
17 gtk3_build_system.patch
18 chemtool.desktop)
19
20prepare() {
21 cd "$srcdir"/chemtool-$pkgver
22 patch -Np1 -i ../gtk3_build_system.patch
23 patch -Np2 -i ../0001-Add-GTK3-compatibility-drawing-layer.patch
24 patch -Np2 -i ../0002-Port-chemtool-sources-to-GTK3.patch
25 ./autogen.sh
26}
27
28build() {
29 cd "$srcdir"/chemtool-$pkgver
30 CFLAGS+=' -fcommon' # https://wiki.gentoo.org/wiki/Gcc_10_porting_notes/fno_common
31 ./configure --prefix=/usr --mandir=/usr/share/man
32 make
33}
34
35package() {
36 cd "$srcdir"/chemtool-$pkgver
37 make DESTDIR="$pkgdir" install
38 install -D -m644 gnome/chemtool.png "$pkgdir"/usr/share/pixmaps/chemtool.png
39 install -D -m644 "$srcdir"/chemtool.desktop "$pkgdir"/usr/share/applications/chemtool.desktop
40}
41
42sha256sums=('86161a0461386b334a5ffb17cdf094a491941884678272f45749813514ddafcb'
43 'b7278a7256ef5c2cfc6ede8e9d577cae662d9e107a3d29b152122f499ffa68b9'
44 'a81ffc0a44b4c856a2633eefcb9d0aced2695c5de0f7bbcb99ba952665a9a8ff'
45 '5cfb774056a88c6e7dcd52233c740a27e592208292e9471e565b86832ec99e16'
46 '9c35347faa7aa664c012f0d66fffbd469c4f2f3f8f24e5dd0cd42d554e9c5ac7')
47

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion