envmerge-git

LOW
maintainer ZAvrikDinozavrik 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Builds the project's own source from a self-hosted Gitea instance (plausibly the maintainer's own infrastructure), compiles a Go binary with standard flags, and installs only the resulting binary and docs; the non-whitelisted host and SKIP checksum are typical for a VCS source but cannot be independently verified.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Builds the project's own source from a self-hosted Gitea instance (plausibly the maintainer's own infrastructure), compiles a Go binary with standard flags, and installs only the resulting binary and docs; the non-whitelisted host and SKIP checksum are typical for a VCS source but cannot be independently verified.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("$pkgname::git+https://git.alexavr.ru/ZAvrikDinozavrik/envmerge.git#branch=master")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: ZAvrikDinozavrik <zaz965@stm32f0.ru>
2pkgname=envmerge-git
3pkgver=r7.bfc5930
4pkgrel=1
5pkgdesc="Merge new keys from .env.example into your .env (TUI + silent mode)"
6arch=('x86_64' 'aarch64')
7url="https://git.alexavr.ru/ZAvrikDinozavrik/envmerge"
8license=('MIT')
9makedepends=('git' 'go')
10provides=('envmerge')
11conflicts=('envmerge')
12source=("$pkgname::git+https://git.alexavr.ru/ZAvrikDinozavrik/envmerge.git#branch=master")
13sha256sums=('SKIP')
14
15pkgver() {
16 cd "$pkgname"
17 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
18}
19
20build() {
21 cd "$pkgname"
22 export CGO_ENABLED=0
23 export GOFLAGS='-mod=vendor -trimpath'
24 export GOPATH="$srcdir/gopath"
25 export GOCACHE="$srcdir/gocache"
26 go build -ldflags "-s -w -X main.version=$pkgver" -o envmerge .
27}
28
29check() {
30 cd "$pkgname"
31 export GOFLAGS='-mod=vendor'
32 export GOPATH="$srcdir/gopath"
33 export GOCACHE="$srcdir/gocache"
34 go test ./...
35}
36
37package() {
38 install -Dm755 "$pkgname/envmerge" "$pkgdir/usr/bin/envmerge"
39 install -Dm644 "$pkgname/README.md" "$pkgdir/usr/share/doc/$pkgname/README.md"
40 install -Dm644 "$pkgname/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
41}
42

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion