harakit-git
maintainer emmatebibyte
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a Git repository hosted on the maintainer's own domain, which is plausibly the project's official home; building from such a source is normal for AUR packages and the worst case of a swapped source is limited to code injection during build, which is already within the trust boundary of using AUR packages.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a Git repository hosted on the maintainer's own domain, which is plausibly the project's official home; building from such a source is normal for AUR packages and the worst case of a swapped source is limited to code injection during build, which is already within the trust boundary of using AUR packages.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
source=("git+https://git.tebibyte.media/bonsai/$_repo.git" "bonsai.sh")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Emma Tebibyte <emma@tebibyte.media>
2
3
_repo=harakit
4
_pkgname=$_repo
5
pkgname=$_pkgname-git
6
pkgver=r682.0e9127d
7
pkgrel=3
8
pkgdesc="New utilities for a new era."
9
arch=('any')
10
url="https://git.tebibyte.media/bonsai/$_repo"
11
license=('AGPL')
12
depends=()
13
makedepends=('rust' 'rust-bindgen')
14
replaces=('bonsai-coreutils-git')
15
source=("git+https://git.tebibyte.media/bonsai/$_repo.git" "bonsai.sh")
16
md5sums=(
17
SKIP
18
ae17ace590d882d9c9701ba4cecbeefe
19
)
20
21
pkgver() {
22
cd "$_repo"
23
( set -o pipefail
24
git describe --long --abbrev=7 2>/dev/null | sed 's/\([^-]*-g\)/r\1/;s/-/./g' ||
25
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
26
)
27
}
28
29
build() {
30
cd "$_repo"
31
make all
32
}
33
34
check() {
35
cd "$_pkgname"
36
make test
37
}
38
39
package() {
40
profile_d="$pkgdir/etc/profile.d"
41
mkdir -p "$profile_d" "$pkgdir/opt/bonsai"
42
cp bonsai.sh "$profile_d"
43
44
cd "$_repo"
45
make PREFIX="$pkgdir/opt/bonsai" install
46
}
47
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |