gog-qfg2
maintainer dcreager
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The non-standard host provides a patch file (SCRIPT.805) for game data, not executable code; the worst case of a swapped source is limited to data tampering, not code execution.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host provides a patch file (SCRIPT.805) for game data, not executable code; the worst case of a swapped source is limited to data tampering, not code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
"http://www.sierrahelp.com/Files/Patches/QuestForGlory/QfG2(QG2IMPRT).zip"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Douglas Creager <dcreager@dcreager.net>
2
pkgname=gog-qfg2
3
pkgver=2.1.0.34
4
pkgrel=3
5
pkgdesc="Quest for Glory 2: Trial by Fire"
6
arch=('x86_64')
7
url="https://www.gog.com/game/quest_for_glory"
8
license=('custom')
9
depends=('dosbox' 'unionfs-fuse')
10
makedepends=('innoextract')
11
source=("local://setup_quest_for_glory2_${pkgver}.exe"
12
"http://www.sierrahelp.com/Files/Patches/QuestForGlory/QfG2(QG2IMPRT).zip"
13
"local://gog-qfg2.desktop"
14
"local://run-qfg2.conf"
15
"local://run-qfg2.sh")
16
sha256sums=('efda9c4ddd5753cbf39a25a3d90337f278ea11bd6c8f6352aab934c9d29a2796'
17
'f1e4f48ec968718896c53cd87a7ae2dd9e5832f8bdc62bb25697d383bd1c0441'
18
'68e6421220d95d4440bfcbd29030133dada506476f11e92b74bd3439937a0ec6'
19
'e8e28abd0667bce3d7fbcb66a814d8f445f1d012ee2b084a8e4a57e342900c6c'
20
'e88ab7fe5da10ddf5e5b1cb68740a16b0406f942792daea91d8015916c1c8765')
21
22
prepare() {
23
innoextract setup_quest_for_glory2_${pkgver}.exe
24
}
25
26
package() {
27
mkdir -p "${pkgdir}/opt/gog"
28
cp -R "${srcdir}/app" "${pkgdir}/opt/gog/qfg2"
29
rm -rf "${pkgdir}/opt/gog/qfg2/DOSBOX"
30
31
# Apply import patch from
32
# http://www.sierrahelp.com/Patches-Updates/Patches-Updates-Games/QuestForGloryUpdates.html#QG2IMPRT
33
cp "${srcdir}/SCRIPT.805" "${pkgdir}/opt/gog/qfg2"
34
35
cp -R "run-qfg2.conf" "${pkgdir}/opt/gog/qfg2"
36
cp -R "run-qfg2.sh" "${pkgdir}/opt/gog/qfg2"
37
# Config file that tells game to use SB instead of Roland MIDI for music
38
#cp -R "RESOURCE.CFG" "${pkgdir}/opt/gog/qfg2"
39
40
mkdir -p "${pkgdir}/usr/share/applications"
41
cp "gog-qfg2.desktop" "${pkgdir}/usr/share/applications"
42
}
43
44
# vim:set ts=2 sw=2 et:
45
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |