classic-addon-manager-git
The package builds from its own source using Go, and the flagged 'external install' via 'go install' is part of the project's build process to fetch development tools (wails3), not a runtime dependency or unverifiable binary execution.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds from its own source using Go, and the flagged 'external install' via 'go install' is part of the project's build process to fetch development tools (wails3), not a runtime dependency or unverifiable binary execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:45
go install github.com/wailsapp/wails/v3/cmd/wails3@latest
PKGBUILD
1 offending line(s) highlighted# Maintainer: atretador
pkgname=classic-addon-manager-git
_pkgname=classic-addon-manager
pkgver=3.0.4.18.g6e1a44d
pkgrel=1
pkgdesc="An addon manager for ArcheAge Classic, built with Go from latest git master"
arch=('x86_64')
url="https://github.com/classic-addon-manager/classic-addon-manager"
license=('MIT')
depends=('glibc')
makedepends=('go' 'npm' 'go-task' 'git' 'gtk3' 'webkit2gtk-4.1')
source=(
"git+$url.git"
"$_pkgname.desktop"
"$_pkgname.install"
"icon.png"
)
sha256sums=('SKIP' 'SKIP' 'SKIP' 'SKIP')
install=$_pkgname.install
pkgver() {
cd "$srcdir/$_pkgname"
git describe --tags --long 2>/dev/null | sed 's/^v//;s/-/./g' || \
echo "r$(git rev-list --count HEAD).$(git rev-parse --short HEAD)"
}
prepare() {
cd "$srcdir/$_pkgname"
cp "$srcdir/$_pkgname.desktop" "$srcdir/$_pkgname/$_pkgname.desktop"
cp "$srcdir/$_pkgname.install" "$srcdir/$_pkgname/$_pkgname.install"
}
build() {
cd "$srcdir/$_pkgname"
export PKG_CONFIG_PATH="/usr/lib/pkgconfig:$PKG_CONFIG_PATH"
export CGO_ENABLED=1
export GOFLAGS="-buildmode=pie -trimpath -mod=readonly -modcacherw"
export GOPATH="${srcdir}/gopath"
mkdir -p "$GOPATH"
export PATH="$GOPATH/bin:$PATH"
go install github.com/wailsapp/wails/v3/cmd/wails3@latest
rm -rf frontend/node_modules frontend/dist
# Build
go-task build:prod
}
package() {
cd "$srcdir/$_pkgname"
# Install binary
install -Dm755 "build/bin/$_pkgname" "$pkgdir/usr/bin/$_pkgname"
# Install desktop file
install -Dm644 "$srcdir/$_pkgname/$_pkgname.desktop" "$pkgdir/usr/share/applications/$_pkgname.desktop"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |