graf

LOW
maintainer marmai 0 votes scanned 2026-10-03 00:23:04.761738
View on AUR
Why flagged

The source is a tarball from the project's own Forgejo repository, which is plausibly the official source; building from project-owned infrastructure, even on a non-whitelisted host, is normal AUR packaging and not inherently dangerous.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's own Forgejo repository, which is plausibly the official source; building from project-owned infrastructure, even on a non-whitelisted host, is normal AUR packaging and not inherently dangerous.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:21 source=("graf-0.8.0.alpha.tar.gz::https://git.sovereign-society.org/graf-vcs/graf/archive/v0.8.0-alpha.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Mark K. <markus@sovereign-society.org>
2# Maintainer note: this package is updated automatically from annotated tags
3# in graf's Forgejo repository via CI.
4
5pkgname=graf
6pkgver=0.8.0.alpha
7pkgrel=1
8pkgdesc='Sovereign-native Janus-native version control for operators and agents'
9arch=('x86_64')
10url='https://git.sovereign-society.org/markus/graf'
11license=('custom:LCL-1.0')
12depends=('glibc')
13makedepends=('bash' 'git' 'janus')
14checkdepends=('bash')
15provides=('graf')
16conflicts=('graf-git')
17
18_upstream_repo='https://git.sovereign-society.org/graf-vcs/graf'
19_upstream_tag='v0.8.0-alpha'
20
21source=("graf-0.8.0.alpha.tar.gz::https://git.sovereign-society.org/graf-vcs/graf/archive/v0.8.0-alpha.tar.gz")
22sha256sums=('e1c6d8b8b0b1bedf31ff379f4f28281b295729e6aadd6bc09c6f7b4fbffc073b')
23
24pkg_source_root() {
25 local marker
26
27 marker="$(find "$srcdir" -maxdepth 4 -type f -path '*/src/main.jan' -print -quit 2>/dev/null)"
28 if [[ -z "$marker" ]]; then
29 return 1
30 fi
31
32 printf '%s' "$(dirname "$marker")"
33}
34
35build() {
36 local graf_root
37
38 graf_root="$(pkg_source_root)"
39 if [[ -z "$graf_root" ]]; then
40 error 'Unable to locate graf source tree in PKGBUILD source extraction path'
41 return 1
42 fi
43
44 if ! command -v janus >/dev/null; then
45 error 'janus compiler not found in build environment'
46 error 'Set build dependency to include janus and ensure it is executable'
47 return 1
48 fi
49
50 cd "$graf_root"
51 JANUS="${JANUS:-$(command -v janus)}" \
52 ./scripts/zb build
53}
54
55check() {
56 local graf_root
57
58 graf_root="$(pkg_source_root)"
59 if [[ -z "$graf_root" ]]; then
60 error 'Unable to locate graf source tree for check()'
61 return 1
62 fi
63
64 if [[ -x "$graf_root/zig-out/bin/graf" ]]; then
65 "$graf_root/zig-out/bin/graf" help >/dev/null 2>&1 || true
66 fi
67}
68
69package() {
70 local graf_root
71
72 graf_root="$(pkg_source_root)"
73 if [[ -z "$graf_root" ]]; then
74 error 'Unable to locate graf source tree for package()'
75 return 1
76 fi
77
78 cd "$graf_root"
79 install -Dm755 zig-out/bin/graf "$pkgdir/usr/bin/graf"
80
81 install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
82
83 if [[ -f "CLAUDE.md" ]]; then
84 install -Dm644 CLAUDE.md "$pkgdir/usr/share/doc/$pkgname/CLAUDE.md"
85 fi
86
87 install -Dm644 docs/agent-native-workflow.md "$pkgdir/usr/share/doc/$pkgname/agent-native-workflow.md"
88}
89

Scan history

Scanned at (UTC)SeverityRules
2026-10-03 00:23:04 Low 2
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion