hexxagon
maintainer carstene1ns
· 8 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is downloaded from the project's own domain (nesqi.se), which is plausibly the maintainer's official site; building from a non-whitelisted but project-owned host is normal for AUR packages and does not constitute a high risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the project's own domain (nesqi.se), which is plausibly the maintainer's official site; building from a non-whitelisted but project-owned host is normal for AUR packages and does not constitute a high risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("http://nesqi.se/download/$pkgname-$pkgver.tar.bz2"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: carstene1ns <arch carsten-teibes de> - http://git.io/ctPKG
2
# Contributor: ploxiln <pierce.lopez@gmail.com>
3
# Contributor: G_Syme <demichan(at)mail(dot)upb(dot)de>
4
5
pkgname=hexxagon
6
pkgver=1.0.2
7
pkgrel=3
8
pkgdesc='A clone of the old DOS game Hexxagon, with enhanced features and strong AI'
9
arch=('i686' 'x86_64')
10
license=('GPL')
11
url='http://www.nesqi.se'
12
depends=('gtkmm')
13
source=("http://nesqi.se/download/$pkgname-$pkgver.tar.bz2"
14
"$pkgname-$pkgver-glibc-2.31.patch"
15
"$pkgname.desktop"
16
"$pkgname.png")
17
sha256sums=('49b13516822fd32a9c58d62735b841a6e47e1714273e03ad20d8a9343a7623cc'
18
'e2564d479a5a3c614c37f043db17b27201f1fd054c1f86028c667eebf25d2926'
19
'673fb40dbfeb96f2594f06f1b105afd23686472d5ef380e8b07d1a0f30b1e822'
20
'0405a14380a379e6502b663d9db77be8471b84aa838fe3f645e25bdbd03c78c7')
21
22
prepare() {
23
# remove timezone redeclarations
24
patch -d $pkgname-$pkgver -Np1 < $pkgname-$pkgver-glibc-2.31.patch
25
}
26
27
build() {
28
cd $pkgname-$pkgver
29
30
# disable glib deprecation warnings
31
export CPPFLAGS="$CPPFLAGS -DGLIB_DISABLE_DEPRECATION_WARNINGS"
32
./configure --prefix=/usr
33
make
34
}
35
36
package() {
37
make -C $pkgname-$pkgver DESTDIR="$pkgdir" install
38
39
# .desktop entry
40
install -Dm644 $pkgname.desktop "$pkgdir"/usr/share/applications/$pkgname.desktop
41
install -Dm644 $pkgname.png "$pkgdir"/usr/share/pixmaps/$pkgname.png
42
}
43
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |