graf
The source is a tarball from the project's own Forgejo repository, which is plausibly the official source; building from project-owned infrastructure, even on a non-whitelisted host, is normal AUR packaging and not inherently dangerous.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's own Forgejo repository, which is plausibly the official source; building from project-owned infrastructure, even on a non-whitelisted host, is normal AUR packaging and not inherently dangerous.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:21
source=("graf-0.8.0.alpha.tar.gz::https://git.sovereign-society.org/graf-vcs/graf/archive/v0.8.0-alpha.tar.gz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Mark K. <markus@sovereign-society.org>
# Maintainer note: this package is updated automatically from annotated tags
# in graf's Forgejo repository via CI.
pkgname=graf
pkgver=0.8.0.alpha
pkgrel=1
pkgdesc='Sovereign-native Janus-native version control for operators and agents'
arch=('x86_64')
url='https://git.sovereign-society.org/markus/graf'
license=('custom:LCL-1.0')
depends=('glibc')
makedepends=('bash' 'git' 'janus')
checkdepends=('bash')
provides=('graf')
conflicts=('graf-git')
_upstream_repo='https://git.sovereign-society.org/graf-vcs/graf'
_upstream_tag='v0.8.0-alpha'
source=("graf-0.8.0.alpha.tar.gz::https://git.sovereign-society.org/graf-vcs/graf/archive/v0.8.0-alpha.tar.gz")
sha256sums=('e1c6d8b8b0b1bedf31ff379f4f28281b295729e6aadd6bc09c6f7b4fbffc073b')
pkg_source_root() {
local marker
marker="$(find "$srcdir" -maxdepth 4 -type f -path '*/src/main.jan' -print -quit 2>/dev/null)"
if [[ -z "$marker" ]]; then
return 1
fi
printf '%s' "$(dirname "$marker")"
}
build() {
local graf_root
graf_root="$(pkg_source_root)"
if [[ -z "$graf_root" ]]; then
error 'Unable to locate graf source tree in PKGBUILD source extraction path'
return 1
fi
if ! command -v janus >/dev/null; then
error 'janus compiler not found in build environment'
error 'Set build dependency to include janus and ensure it is executable'
return 1
fi
cd "$graf_root"
JANUS="${JANUS:-$(command -v janus)}" \
./scripts/zb build
}
check() {
local graf_root
graf_root="$(pkg_source_root)"
if [[ -z "$graf_root" ]]; then
error 'Unable to locate graf source tree for check()'
return 1
fi
if [[ -x "$graf_root/zig-out/bin/graf" ]]; then
"$graf_root/zig-out/bin/graf" help >/dev/null 2>&1 || true
fi
}
package() {
local graf_root
graf_root="$(pkg_source_root)"
if [[ -z "$graf_root" ]]; then
error 'Unable to locate graf source tree for package()'
return 1
fi
cd "$graf_root"
install -Dm755 zig-out/bin/graf "$pkgdir/usr/bin/graf"
install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
if [[ -f "CLAUDE.md" ]]; then
install -Dm644 CLAUDE.md "$pkgdir/usr/share/doc/$pkgname/CLAUDE.md"
fi
install -Dm644 docs/agent-native-workflow.md "$pkgdir/usr/share/doc/$pkgname/agent-native-workflow.md"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |