dayjournal
maintainer JoeBlakeB
· 2 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package builds from a source tarball hosted on Launchpad, a legitimate platform, and includes non-executable assets (icon, desktop file) from a personal domain; the worst case of a swapped asset is limited to cosmetic or data tampering, not code execution.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The package builds from a source tarball hosted on Launchpad, a legitimate platform, and includes non-executable assets (icon, desktop file) from a personal domain; the worst case of a swapped asset is limited to cosmetic or data tampering, not code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
'https://iballwasrawt.ru/dayjournal/dayjournal.png'
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Ivan Semkin (ivan at semkin dot ru)
2
3
appname=DayJournal
4
pkgname=dayjournal
5
pkgver=23.0.6
6
pkgrel=1
7
pkgdesc="A minimalistic digital journal that lets the content you create outlast DayJournal itself"
8
arch=('any')
9
url="https://burnsoftware.wordpress.com/dayjournal/"
10
license=('GPL3')
11
depends=('gdk-pixbuf2' 'libgee' 'glib2' 'gtk3' 'libnotify' 'pango')
12
provides=('dayjournal')
13
conflicts=('dayjournal')
14
15
source=("https://launchpad.net/~thejambi/+archive/ubuntu/thejambi/+files/dayjournal_$pkgver.orig.tar.gz"
16
'https://iballwasrawt.ru/dayjournal/dayjournal.png'
17
'https://iballwasrawt.ru/dayjournal/dayjournal.desktop')
18
sha256sums=('92a1f3a167a2ea038716ec8b1fc4a2920fff8185e1fd1b3b36ae020ada3d690d'
19
'901d182afa6c838077cb163edb80d1e76e23f3bdd9f436797d82a7f7560ac664'
20
'1c2e09afd5fc1c6b5ac4b1fd807b1827462a89d824f0c09f5689b8a81dee294a')
21
22
prepare() {
23
cd "${srcdir}/${pkgname}-${pkgver}"
24
sed -i 's| appindicator3-0.1||' configure
25
}
26
27
build() {
28
cd "${srcdir}/${pkgname}-${pkgver}"
29
./configure
30
make
31
}
32
33
package() {
34
install -d "${pkgdir}/usr/bin"
35
install -d "${pkgdir}/usr/share/applications"
36
install -d "${pkgdir}/usr/share/icons"
37
38
install -m755 "${srcdir}/${pkgname}-${pkgver}/src/${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
39
install -m644 "${srcdir}/${pkgname}.png" "${pkgdir}/usr/share/icons/${pkgname}.png"
40
install -m644 "${srcdir}/${pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname}.desktop"
41
}
42
# vim:set ts=2 sw=2 et:
43
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |