fldigi

LOW
maintainer not_anonymous 62 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is downloaded from the project's official domain (w1hkj.org), which is not on the standard whitelist but is legitimate for this software; building from official project sources is normal AUR practice and poses low risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the project's official domain (w1hkj.org), which is not on the standard whitelist but is legitimate for this software; building from official project sources is normal AUR practice and poses low risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source=(http://w1hkj.org/files/$pkgname/$pkgname-$pkgver.tar.gz

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: not_anonymous <nmlibertarian@gmail.com>
2# Previous Maintainers: Andreas Schreiner <andreas.schreiner@sonnenmulde.at>
3# and: [Vitaliy Berdinskikh](mailto:ur6lad@archlinux.org.ua) aka UR6LAD
4# Original Submission: Bob Finch <w9ya@qrparci.net>
5
6pkgname=fldigi
7pkgver=4.2.12
8pkgrel=2
9pkgdesc="Digital Modem Program for Amateur Radio"
10arch=('i686' 'x86_64' 'aarch64')
11url="http://w1hkj.org"
12license=('GPL-2.0-or-later')
13depends=('cty' 'fltk' 'libsamplerate' 'flxmlrpc>=1.0.1' 'libsndfile'
14 'portaudio' 'libpulse' 'libgpiod' 'hamlib' 'hamradio-menus')
15optdepends=('pulseaudio: pulseaudio support')
16source=(http://w1hkj.org/files/$pkgname/$pkgname-$pkgver.tar.gz
17# diff.wayland.fix)
18 flarq.wayland.patch)
19
20prepare () {
21 cd $srcdir/$pkgname-$pkgver
22
23# patch -p0 < ../diff.wayland.fix
24 patch -p0 < ../flarq.wayland.patch
25}
26
27build() {
28 cd "$srcdir"/$pkgname-$pkgver
29
30 ./configure --prefix=/usr \
31 --enable-tls --with-flxmlrpc --without-asciidoc
32# --enable-tls --without-flxmlrpc --without-asciidoc
33# (^^^ temporary, until flxmlrpc is updated)
34 make ASCIIDOC_ICONS_DIR=/etc/asciidoc/images/icons/
35}
36
37check() {
38 cd "$srcdir"/$pkgname-$pkgver
39
40 make -k check
41}
42
43package() {
44 cd "$srcdir"/$pkgname-$pkgver
45
46 make DESTDIR="$pkgdir" install
47}
48md5sums=('2138b4eff9cd51f7824b79e1b751da1c'
49 'c180f454288d495ecbc65b364818530d')
50sha256sums=('028bcb1c100cb790cad36324b8063c13594e160743f9378320ceabcf16dbc44a'
51 '3bdbd3fe1b8d7864f46418606e1ab98ca45b48fecd2338a573074c4185dbf380')
52

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 17:18:20 Medium 1
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion