dn-git
The source is a git repository hosted on the maintainer's own domain, which is plausibly the project's official source; building from a non-whitelisted host is normal for AUR packages when it is the project's own forge.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a git repository hosted on the maintainer's own domain, which is plausibly the project's official source; building from a non-whitelisted host is normal for AUR packages when it is the project's own forge.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:46
"git+https://git.janouch.name/p/$_pkgname.git"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Přemysl Eric Janouch <p@janouch.name>
pkgname=dn-git
_pkgname=dawn
pkgver=r61.219393c
pkgrel=6
pkgdesc="Colour-managed image browser"
url="https://git.janouch.name/p/dawn"
arch=('x86_64')
license=('MPL-2.0')
conflicts=('dn')
provides=('dn')
makedepends=(
'cmake'
'git'
'glslang'
'librsvg'
'pkg-config'
'vulkan-headers'
)
depends=(
'libcolord'
'libjpeg-turbo'
'libwebp'
'qt6-base'
'resvg'
'shared-mime-info'
'vulkan-driver'
'vulkan-icd-loader'
'wayland-protocols'
)
optdepends=(
'gdk-pixbuf2: GdkPixbuf module support'
'glycin: Glycin module support'
'jxrlib: JPEG XR'
'libheif: HEIF images'
'libjxl: JPEG XL'
'libraw: raw photo images'
'librsvg: SVG images'
'libtiff: TIFF images'
'libxcursor: X cursor images'
'openjpeg2: JPEG2000'
'perl-image-exiftool: file information'
)
install=dn.install
source=(
"git+https://git.janouch.name/p/$_pkgname.git"
update-dn-desktop-files.hook
)
sha256sums=(
SKIP
baa1bcd3bc55eacd28ad54e78b64d1f872d3e40100bb98a1af43d7ba0d4743bd
)
pkgver() {
cd "$srcdir/$_pkgname"
( set -o pipefail
git describe --long --tags 2>/dev/null | sed 's/\([^-]*-g\)/r\1/;s/-/./g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
)
}
prepare() {
cd "$srcdir/$_pkgname"
git submodule init
git submodule update
}
build() {
rm -rf "$srcdir/$_pkgname-build"
mkdir "$srcdir/$_pkgname-build"
cd "$srcdir/$_pkgname-build"
cmake "$srcdir/$_pkgname" -DCMAKE_BUILD_TYPE=None \
-DCMAKE_INSTALL_PREFIX=/usr
make
}
package() {
cd "$srcdir/$_pkgname-build"
make install DESTDIR="$pkgdir"
install -Dm644 "$srcdir/$_pkgname/LICENSE" \
"$pkgdir/usr/share/licenses/$pkgname/LICENSE"
install -Dt "$pkgdir/usr/share/libalpm/hooks" -m644 \
"$srcdir/update-dn-desktop-files.hook"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-09 00:05:33 | Low | 2 |
| 2026-10-08 00:28:03 | Low | 2 |
| 2026-10-07 00:21:34 | Low | 2 |
| 2026-10-06 00:13:36 | Low | 2 |
| 2026-10-05 00:08:03 | Low | 2 |
| 2026-10-04 00:18:08 | Low | 2 |
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |