chemtool-proper

maintainer ConnorBehan · 3 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from a university-hosted personal page, which is not on a standard code forge but plausibly the original developer's official site; it is a standard source tarball for a known software, built locally with patches, and no untrusted executables or remote code execution occur.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from a university-hosted personal page, which is not on a standard code forge but plausibly the original developer's official site; it is a standard source tarball for a known software, built locally with patches, and no untrusted executables or remote code execution occur.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz

PKGBUILD

1 offending line(s) highlighted
1# Contributor: Connor Behan <connor.behan@gmail.com>
2
3pkgname=chemtool-proper
4pkgver=1.6.14
5pkgrel=3
6pkgdesc="Chemtool ported to Gtk3 with assistance from Codex"
7arch=(i686 x86_64)
8license=('GPL2')
9url="http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool.html"
10depends=('gtk3')
11replaces=('chemtool')
12provides=('chemtool')
13options=(!libtool)
14source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz
15 0001-Add-GTK3-compatibility-drawing-layer.patch
16 0002-Port-chemtool-sources-to-GTK3.patch
17 gtk3_build_system.patch
18 chemtool.desktop)
19
20prepare() {
21 cd "$srcdir"/chemtool-$pkgver
22 patch -Np1 -i ../gtk3_build_system.patch
23 patch -Np2 -i ../0001-Add-GTK3-compatibility-drawing-layer.patch
24 patch -Np2 -i ../0002-Port-chemtool-sources-to-GTK3.patch
25 ./autogen.sh
26}
27
28build() {
29 cd "$srcdir"/chemtool-$pkgver
30 CFLAGS+=' -fcommon' # https://wiki.gentoo.org/wiki/Gcc_10_porting_notes/fno_common
31 ./configure --prefix=/usr --mandir=/usr/share/man
32 make
33}
34
35package() {
36 cd "$srcdir"/chemtool-$pkgver
37 make DESTDIR="$pkgdir" install
38 install -D -m644 gnome/chemtool.png "$pkgdir"/usr/share/pixmaps/chemtool.png
39 install -D -m644 "$srcdir"/chemtool.desktop "$pkgdir"/usr/share/applications/chemtool.desktop
40}
41
42sha256sums=('86161a0461386b334a5ffb17cdf094a491941884678272f45749813514ddafcb'
43 'b7278a7256ef5c2cfc6ede8e9d577cae662d9e107a3d29b152122f499ffa68b9'
44 'a81ffc0a44b4c856a2633eefcb9d0aced2695c5de0f7bbcb99ba952665a9a8ff'
45 '5cfb774056a88c6e7dcd52233c740a27e592208292e9471e565b86832ec99e16'
46 '9c35347faa7aa664c012f0d66fffbd469c4f2f3f8f24e5dd0cd42d554e9c5ac7')
47

Changes since previous scan

--- PKGBUILD @ 2026-07-22 00:29
+++ PKGBUILD @ 2026-08-03 00:08
@@ -2,20 +2,31 @@
pkgname=chemtool-proper
pkgver=1.6.14
-pkgrel=2
-pkgdesc="Chemtool without the stupid right justified help menu"
+pkgrel=3
+pkgdesc="Chemtool ported to Gtk3 with assistance from Codex"
arch=(i686 x86_64)
license=('GPL2')
url="http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool.html"
-depends=('gtk2')
+depends=('gtk3')
replaces=('chemtool')
provides=('chemtool')
options=(!libtool)
-source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz chemtool.desktop)
+source=(http://ruby.chemie.uni-freiburg.de/~martin/chemtool/chemtool-$pkgver.tar.gz
+ 0001-Add-GTK3-compatibility-drawing-layer.patch
+ 0002-Port-chemtool-sources-to-GTK3.patch
+ gtk3_build_system.patch
+ chemtool.desktop)
+
+prepare() {
+ cd "$srcdir"/chemtool-$pkgver
+ patch -Np1 -i ../gtk3_build_system.patch
+ patch -Np2 -i ../0001-Add-GTK3-compatibility-drawing-layer.patch
+ patch -Np2 -i ../0002-Port-chemtool-sources-to-GTK3.patch
+ ./autogen.sh
+}
build() {
cd "$srcdir"/chemtool-$pkgver
- sed -i -e 's/.*right_justify.*//g' main.c
CFLAGS+=' -fcommon' # https://wiki.gentoo.org/wiki/Gcc_10_porting_notes/fno_common
./configure --prefix=/usr --mandir=/usr/share/man
make
@@ -28,6 +39,9 @@
install -D -m644 "$srcdir"/chemtool.desktop "$pkgdir"/usr/share/applications/chemtool.desktop
}
-md5sums=('3a97680f0abe1327af1f0072551a68e2'
- '8cbb6f7021bd5aaa6f6a31fc4d95a06e')
+sha256sums=('86161a0461386b334a5ffb17cdf094a491941884678272f45749813514ddafcb'
+ 'b7278a7256ef5c2cfc6ede8e9d577cae662d9e107a3d29b152122f499ffa68b9'
+ 'a81ffc0a44b4c856a2633eefcb9d0aced2695c5de0f7bbcb99ba952665a9a8ff'
+ '5cfb774056a88c6e7dcd52233c740a27e592208292e9471e565b86832ec99e16'
+ '9c35347faa7aa664c012f0d66fffbd469c4f2f3f8f24e5dd0cd42d554e9c5ac7')

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 05:19:42 MEDIUM 1
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion