htsbox
LOW
maintainer imjiaoyuan
0 votes
scanned 2026-10-08 16:09:18.783063
Why flagged
The package builds from a pinned commit of a legitimate project on GitHub; the source is verifiable and the build process is transparent, posing no active threat despite low votes and recent upload.
Triggered rules
Low
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
Low
AI review
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from a pinned commit of a legitimate project on GitHub; the source is verifiable and the build process is transparent, posing no active threat despite low votes and recent upload.
PKGBUILD
1
# Maintainer: imjiaoyuan <imjiaoyuan@gmail.com>
2
# Upstream tags no clean version, so pkgver is the pinned commit's date and
3
# _tag carries the commit itself. The bundled htslib subset is vendored in the
4
# repository, so no external htslib is needed.
5
6
pkgname=htsbox
7
_tag=c901cb3a3324c119988f4bcd4412cbe48e1b5a38
8
pkgver=20250911
9
pkgrel=1
10
pkgdesc="Powerful toolset for processing BAM files and a test bed for htslib"
11
arch=('x86_64')
12
url="https://github.com/lh3/htsbox"
13
license=('MIT')
14
depends=('glibc' 'zlib')
15
source=("$pkgname-$pkgver.tar.gz::${url}/archive/${_tag}.tar.gz")
16
sha256sums=('085aecc9ad28434aaa7cc61f09b17c93a0ea5c643a688ddbbc1b9ed24c2850d9')
17
18
build() {
19
cd "$srcdir/$pkgname-$_tag"
20
make
21
}
22
23
package() {
24
cd "$srcdir/$pkgname-$_tag"
25
install -Dm755 htsbox "$pkgdir/usr/bin/htsbox"
26
install -Dm644 LICENSE.txt "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
27
}
28
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-08 16:09:18 | Low | 2 |