gtm-player
The package builds from source hosted on GitHub (plausibly the project's own), uses a SKIP'd checksum which is suboptimal but not inherently dangerous, and installs only compiled binaries, man pages, completions, and config files without executing remote code or downloading unverified payloads.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from source hosted on GitHub (plausibly the project's own), uses a SKIP'd checksum which is suboptimal but not inherently dangerous, and installs only compiled binaries, man pages, completions, and config files without executing remote code or downloading unverified payloads.
PKGBUILD
# Maintainer: Your Name <your.email@example.com>
pkgname=gtm-player
_pkgname=gtm
pkgver=0.2.88
pkgrel=1
pkgdesc='Reimagined terminal audio player with background daemon, YouTube/Spotify, radio and podcasts'
arch=('x86_64' 'aarch64')
url='https://gtmd.dev'
license=('GPL-3.0-only')
depends=('alsa-lib' 'dbus' 'gcc-libs' 'glibc')
makedepends=('cargo' 'pandoc' 'pkgconf')
optdepends=('yt-dlp: download YouTube audio and resolve Spotify tracks for offline playback'
'ffmpeg: audio conversion for downloaded tracks'
'pipewire-alsa: PipeWire audio output through the ALSA backend')
source=("$_pkgname-$pkgver.tar.gz::https://github.com/prjctimg/gtm/archive/refs/tags/v$pkgver.tar.gz")
sha256sums=('SKIP') # replace with the real checksum: run `updpkgsums`
prepare() {
cd "$_pkgname-$pkgver"
export RUSTUP_TOOLCHAIN=stable
cargo fetch --locked --target "$(rustc -vV | sed -n 's/host: //p')"
}
build() {
cd "$_pkgname-$pkgver"
export RUSTUP_TOOLCHAIN=stable
export CARGO_TARGET_DIR=target
cargo build --frozen --release
# Man pages (pandoc) and shell completions generated by the built binaries
./scripts/build/manpages.sh artifacts
./scripts/build/completions.sh "$PWD/artifacts"
}
package() {
cd "$_pkgname-$pkgver"
# Binaries
install -Dm755 target/release/gtm "$pkgdir/usr/bin/gtm"
install -Dm755 target/release/gtmd "$pkgdir/usr/bin/gtmd"
# Man pages
install -Dm644 artifacts/man/gtm.1 "$pkgdir/usr/share/man/man1/gtm.1"
install -Dm644 artifacts/man/gtmd.1 "$pkgdir/usr/share/man/man1/gtmd.1"
install -Dm644 artifacts/man/gtmd-ipc.1 "$pkgdir/usr/share/man/man1/gtmd-ipc.1"
# Shell completions (bash, zsh, fish)
install -Dm644 artifacts/completions/gtm.bash "$pkgdir/usr/share/bash-completion/completions/gtm"
install -Dm644 artifacts/completions/gtmd.bash "$pkgdir/usr/share/bash-completion/completions/gtmd"
install -Dm644 artifacts/completions/_gtm "$pkgdir/usr/share/zsh/site-functions/_gtm"
install -Dm644 artifacts/completions/_gtmd "$pkgdir/usr/share/zsh/site-functions/_gtmd"
install -Dm644 artifacts/completions/gtm.fish "$pkgdir/usr/share/fish/vendor_completions.d/gtm.fish"
install -Dm644 artifacts/completions/gtmd.fish "$pkgdir/usr/share/fish/vendor_completions.d/gtmd.fish"
# systemd user unit, pointed at the packaged binary path
install -Dm644 dist/gtmd.service "$pkgdir/usr/lib/systemd/user/gtmd.service"
sed -i 's|^ExecStart=[^ ]*gtmd\b|ExecStart=/usr/bin/gtmd|' \
"$pkgdir/usr/lib/systemd/user/gtmd.service"
# License and docs
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-07 14:05:47 | Low | 2 |