envmerge-git
Builds the project's own source from a self-hosted Gitea instance (plausibly the maintainer's own infrastructure), compiles a Go binary with standard flags, and installs only the resulting binary and docs; the non-whitelisted host and SKIP checksum are typical for a VCS source but cannot be independently verified.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Builds the project's own source from a self-hosted Gitea instance (plausibly the maintainer's own infrastructure), compiles a Go binary with standard flags, and installs only the resulting binary and docs; the non-whitelisted host and SKIP checksum are typical for a VCS source but cannot be independently verified.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("$pkgname::git+https://git.alexavr.ru/ZAvrikDinozavrik/envmerge.git#branch=master")
PKGBUILD
1 offending line(s) highlighted# Maintainer: ZAvrikDinozavrik <zaz965@stm32f0.ru>
pkgname=envmerge-git
pkgver=r7.bfc5930
pkgrel=1
pkgdesc="Merge new keys from .env.example into your .env (TUI + silent mode)"
arch=('x86_64' 'aarch64')
url="https://git.alexavr.ru/ZAvrikDinozavrik/envmerge"
license=('MIT')
makedepends=('git' 'go')
provides=('envmerge')
conflicts=('envmerge')
source=("$pkgname::git+https://git.alexavr.ru/ZAvrikDinozavrik/envmerge.git#branch=master")
sha256sums=('SKIP')
pkgver() {
cd "$pkgname"
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
}
build() {
cd "$pkgname"
export CGO_ENABLED=0
export GOFLAGS='-mod=vendor -trimpath'
export GOPATH="$srcdir/gopath"
export GOCACHE="$srcdir/gocache"
go build -ldflags "-s -w -X main.version=$pkgver" -o envmerge .
}
check() {
cd "$pkgname"
export GOFLAGS='-mod=vendor'
export GOPATH="$srcdir/gopath"
export GOCACHE="$srcdir/gocache"
go test ./...
}
package() {
install -Dm755 "$pkgname/envmerge" "$pkgdir/usr/bin/envmerge"
install -Dm644 "$pkgname/README.md" "$pkgdir/usr/share/doc/$pkgname/README.md"
install -Dm644 "$pkgname/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Low | 3 |
| 2026-10-06 00:13:36 | Low | 3 |
| 2026-10-05 23:40:58 | Medium | 2 |