gtm-player

LOW
maintainer vaishnav 0 votes scanned 2026-10-07 14:05:47.471701
View on AUR
Why flagged

The package builds from source hosted on GitHub (plausibly the project's own), uses a SKIP'd checksum which is suboptimal but not inherently dangerous, and installs only compiled binaries, man pages, completions, and config files without executing remote code or downloading unverified payloads.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from source hosted on GitHub (plausibly the project's own), uses a SKIP'd checksum which is suboptimal but not inherently dangerous, and installs only compiled binaries, man pages, completions, and config files without executing remote code or downloading unverified payloads.

PKGBUILD

1# Maintainer: Your Name <your.email@example.com>
2
3pkgname=gtm-player
4_pkgname=gtm
5pkgver=0.2.88
6pkgrel=1
7pkgdesc='Reimagined terminal audio player with background daemon, YouTube/Spotify, radio and podcasts'
8arch=('x86_64' 'aarch64')
9url='https://gtmd.dev'
10license=('GPL-3.0-only')
11depends=('alsa-lib' 'dbus' 'gcc-libs' 'glibc')
12makedepends=('cargo' 'pandoc' 'pkgconf')
13optdepends=('yt-dlp: download YouTube audio and resolve Spotify tracks for offline playback'
14 'ffmpeg: audio conversion for downloaded tracks'
15 'pipewire-alsa: PipeWire audio output through the ALSA backend')
16source=("$_pkgname-$pkgver.tar.gz::https://github.com/prjctimg/gtm/archive/refs/tags/v$pkgver.tar.gz")
17sha256sums=('SKIP') # replace with the real checksum: run `updpkgsums`
18
19prepare() {
20 cd "$_pkgname-$pkgver"
21 export RUSTUP_TOOLCHAIN=stable
22 cargo fetch --locked --target "$(rustc -vV | sed -n 's/host: //p')"
23}
24
25build() {
26 cd "$_pkgname-$pkgver"
27 export RUSTUP_TOOLCHAIN=stable
28 export CARGO_TARGET_DIR=target
29 cargo build --frozen --release
30
31 # Man pages (pandoc) and shell completions generated by the built binaries
32 ./scripts/build/manpages.sh artifacts
33 ./scripts/build/completions.sh "$PWD/artifacts"
34}
35
36package() {
37 cd "$_pkgname-$pkgver"
38
39 # Binaries
40 install -Dm755 target/release/gtm "$pkgdir/usr/bin/gtm"
41 install -Dm755 target/release/gtmd "$pkgdir/usr/bin/gtmd"
42
43 # Man pages
44 install -Dm644 artifacts/man/gtm.1 "$pkgdir/usr/share/man/man1/gtm.1"
45 install -Dm644 artifacts/man/gtmd.1 "$pkgdir/usr/share/man/man1/gtmd.1"
46 install -Dm644 artifacts/man/gtmd-ipc.1 "$pkgdir/usr/share/man/man1/gtmd-ipc.1"
47
48 # Shell completions (bash, zsh, fish)
49 install -Dm644 artifacts/completions/gtm.bash "$pkgdir/usr/share/bash-completion/completions/gtm"
50 install -Dm644 artifacts/completions/gtmd.bash "$pkgdir/usr/share/bash-completion/completions/gtmd"
51 install -Dm644 artifacts/completions/_gtm "$pkgdir/usr/share/zsh/site-functions/_gtm"
52 install -Dm644 artifacts/completions/_gtmd "$pkgdir/usr/share/zsh/site-functions/_gtmd"
53 install -Dm644 artifacts/completions/gtm.fish "$pkgdir/usr/share/fish/vendor_completions.d/gtm.fish"
54 install -Dm644 artifacts/completions/gtmd.fish "$pkgdir/usr/share/fish/vendor_completions.d/gtmd.fish"
55
56 # systemd user unit, pointed at the packaged binary path
57 install -Dm644 dist/gtmd.service "$pkgdir/usr/lib/systemd/user/gtmd.service"
58 sed -i 's|^ExecStart=[^ ]*gtmd\b|ExecStart=/usr/bin/gtmd|' \
59 "$pkgdir/usr/lib/systemd/user/gtmd.service"
60
61 # License and docs
62 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
63 install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
64}
65

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 14:05:47 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion