hinoirisetr
Builds the project's own source from a personal Gitea instance via git+https; the non-whitelisted host is plausibly the project's own forge, the binary is compiled from source (not a prebuilt), and SKIP on a git source is normal AUR practice — low risk, just unverifiable if the host were compromised.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 80%): Builds the project's own source from a personal Gitea instance via git+https; the non-whitelisted host is plausibly the project's own forge, the binary is compiled from source (not a prebuilt), and SKIP on a git source is normal AUR practice — low risk, just unverifiable if the host were compromised.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
source=("git+https://git.vavakado.xyz/me/hinoirisetr.git")
PKGBUILD
1 offending line(s) highlighted# SPDX-License-Identifier: 0BSD
# Maintainer: a-catgirl <paws@a-catgirl.dev>
# pulls in `pandoc-cli` as a makedepend
: "${_generate_manual_page:=no}"
pkgname=hinoirisetr
pkgver=1.6.3
_pkgver=1.6.3
pkgrel=2
pkgdesc="A lightweight daemon that automatically adjusts your screen's color temperature and gamma based on the time of day"
arch=("i686" "x86_64" "aarch64")
url="https://git.vavakado.xyz/me/hinoirisetr.git"
license=("MIT")
makedepends=("cargo" "git")
source=("git+https://git.vavakado.xyz/me/hinoirisetr.git")
optdepends=(
"ddcutil: ddcutil backend support"
"hyprsunset: hyprland backend support"
"wayland"
"xsct: xsct backend support"
"libnotify: desktop notifications support")
sha256sums=("SKIP")
if [[ $_generate_manual_page == "yes" ]]; then
makedepends+=("pandoc-cli")
fi
prepare() {
cd "$pkgname"
git config --local advice.detachedHead false
git checkout tags/v${_pkgver}
}
build() {
cd "$pkgname"
cargo build --release
if [[ $_generate_manual_page == "yes" ]]; then
pandoc manpages/hinoirisetr.1.md -s -t man -o manpages/hinoirisetr.1
fi
}
package() {
cd "$pkgname"
install -Dm755 "target/release/hinoirisetr" "$pkgdir/usr/bin/hinoirisetr"
if [[ $_generate_manual_page == "yes" ]]; then
install -Dm644 "manpages/hinoirisetr.1" "$pkgdir/usr/share/man/man1/hinoirisetr.1"
fi
install -Dm644 "LICENSE" "$pkgdir/usr/share/licenses/${pkgname}/LICENSE-MIT"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |