fermikit

LOW
maintainer imjiaoyuan 0 votes scanned 2026-10-08 18:09:39.829306
View on AUR
Why flagged

The package builds from source using pinned git commits from the original author's GitHub repositories; the low severity is due to SKIP'd checksums and few votes, but all sources are legitimate project components with no remote code execution or malicious behavior.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from source using pinned git commits from the original author's GitHub repositories; the low severity is due to SKIP'd checksums and few votes, but all sources are legitimate project components with no remote code execution or malicious behavior.

PKGBUILD

1# Maintainer: imjiaoyuan <imjiaoyuan@gmail.com>
2# FermiKit ships as a self-contained `fermi.kit` directory: the pipeline scripts
3# locate their helper binaries (bwa, ropebwt2, htsbox, bfc, seqtk, trimadap-mt,
4# k8) relative to their own path, so the kit is installed as a unit and the two
5# documented entry points are exposed through exec wrappers that keep that path.
6# lh3's code is MIT; the kit bundles bwa, which is GPL-3.0, hence the aggregate.
7
8pkgname=fermikit
9pkgver=0.13
10pkgrel=1
11pkgdesc="De novo assembly based variant calling pipeline for Illumina short reads"
12arch=('x86_64')
13url="https://github.com/lh3/fermikit"
14license=('MIT' 'GPL-3.0-or-later')
15depends=('glibc' 'perl' 'zlib')
16makedepends=('git')
17source=(
18 "fermikit::git+${url}.git#tag=v${pkgver}"
19 "bfc::git+https://github.com/lh3/bfc.git#commit=a73dad248dc56d9d4d22eacbbbc51ac276045168"
20 "bwa::git+https://github.com/lh3/bwa.git#commit=eb428d7d31ced059ad39af2701a22ebe6d175657"
21 "fermi2::git+https://github.com/lh3/fermi2.git#commit=ee4c2349b387e628e402f6daa5815ca5c2e12fbf"
22 "hapdip::git+https://github.com/lh3/hapdip.git#commit=84c851465f609cbb324009e5a7a7ae1774719c4a"
23 "htsbox::git+https://github.com/lh3/htsbox.git#commit=7db14a0a83a64cc3a23820bd029802f298fabe7b"
24 "ropebwt2::git+https://github.com/lh3/ropebwt2.git#commit=e23a7df263571c02aa0c0434e623108482097e3d"
25 "seqtk::git+https://github.com/lh3/seqtk.git#commit=5e1e8dbd506ea1ff8c77d468a1f27b8e8f73eac0"
26 "trimadap::git+https://github.com/lh3/trimadap.git#commit=b8eb2f4fee84180d1d4af4929af1571f8cb3c53d"
27)
28sha256sums=('SKIP'
29 'SKIP'
30 'SKIP'
31 'SKIP'
32 'SKIP'
33 'SKIP'
34 'SKIP'
35 'SKIP'
36 'SKIP')
37
38prepare() {
39 cd "$srcdir/fermikit"
40 # the submodule checkouts come from the git sources above
41 for sub in bfc bwa fermi2 hapdip htsbox ropebwt2 seqtk trimadap; do
42 rm -rf "$sub"
43 mkdir -p "$sub"
44 cp -a "$srcdir/$sub/." "$sub/"
45 rm -rf "$sub/.git"
46 done
47}
48
49build() {
50 cd "$srcdir/fermikit"
51 # htsbox's ksort.h helpers are static inline and go missing when LTO is on;
52 # ropebwt2's rle.h defines rle_auxtab rather than declaring it extern, which
53 # GCC 10+ rejects without the old common-symbol behaviour.
54 export CFLAGS="${CFLAGS//-flto=auto/}"
55 make CFLAGS="$CFLAGS -fcommon"
56}
57
58package() {
59 cd "$srcdir/fermikit"
60 install -d "$pkgdir/usr/lib/$pkgname"
61 cp -a fermi.kit "$pkgdir/usr/lib/$pkgname/fermi.kit"
62 install -d "$pkgdir/usr/bin"
63 for prog in fermi2.pl run-calling; do
64 printf '#!/bin/sh\nexec /usr/lib/fermikit/fermi.kit/%s "$@"\n' "$prog" \
65 > "$pkgdir/usr/bin/$prog"
66 chmod 755 "$pkgdir/usr/bin/$prog"
67 done
68 # lh3's own code is MIT (the kit ships no LICENSE file); the grant is the
69 # MIT block in the klib headers the tools bundle
70 awk 'NR==1,/^\*\//' "$srcdir/fermi2/kseq.h" > LICENSE
71 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
72}
73

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 18:09:39 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion