hunspell-pt-br
The source is an .oxt file from the official LibreOffice extensions site, which is a legitimate source for this package;虽 host not whitelisted, it is plausibly official, and the package installs only dictionary data, not executable code.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is an .oxt file from the official LibreOffice extensions site, which is a legitimate source for this package;虽 host not whitelisted, it is plausibly official, and the package installs only dictionary data, not executable code.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=('https://extensions.libreoffice.org/assets/downloads/z/veroptbrv320aoc.oxt')
PKGBUILD
1 offending line(s) highlighted# Maintainer: Henrique Custódio <henriqueffc at tutanota dot com>
# Maintainer: Rafael Fontenelle <rafaelff@gnome.org>
# Contributor: Pedro Gabriel Drumond Pereira <pedrogabriel at dcc.ufmg.br>
# Contributor: Rafael D Martins <raziel_takato at hotmail dotcom>
# Contributor: Daniel Felipe Reis Apolinario <dapolinario at gmail dotcom>
# Contributor: Bernardo Barros <bernardobarros at gmail dotcom>
# Contributor: Robson R S Peixoto <robsonpeixoto at gmail dotcom>
pkgname=hunspell-pt-br
pkgver=3.2.0
pkgrel=2
epoch=1
pkgdesc="Brazillian Portuguese grammar, spelling and hyphenation checker to hunspell"
arch=(any)
url="https://extensions.libreoffice.org/en/extensions/show/vero-verificador-ortografico-e-hifenizador-em-portugues"
license=('LGPL-3.0-only' 'MPL')
makedepends=('qt6-webengine')
optdepends=('hunspell: the spell checking libraries and apps')
source=('https://extensions.libreoffice.org/assets/downloads/z/veroptbrv320aoc.oxt')
sha256sums=('78bac9ed27bf1b23666e240bc3809b9520004f14885423580a029771032bff54')
# based it in the community build for hunspell-hu-HU
package() {
cd "$srcdir"
install -dm755 "$pkgdir"/usr/share/hunspell
install -m644 -t "$pkgdir"/usr/share/hunspell pt_BR.dic pt_BR.aff
# Install webengine dictionaries
install -d "$pkgdir"/usr/share/qt{,6}/qtwebengine_dictionaries/
for _file in "$pkgdir"/usr/share/hunspell/*.dic; do
_filename=$(basename $_file)
/usr/lib/qt6/qwebengine_convert_dict $_file "$pkgdir"/usr/share/qt6/qtwebengine_dictionaries/${_filename/\.dic/\.bdic}
ln -rs "$pkgdir"/usr/share/qt6/qtwebengine_dictionaries/${_filename/\.dic/\.bdic} "$pkgdir"/usr/share/qt/qtwebengine_dictionaries/
done
# the symlinks
install -dm755 "$pkgdir"/usr/share/myspell/dicts
pushd "$pkgdir"/usr/share/myspell/dicts
for file in "$pkgdir"/usr/share/hunspell/*; do
ln -sv /usr/share/hunspell/$(basename $file) .
done
popd
# docs
install -Dm644 README_pt_BR.txt "$pkgdir"/usr/share/doc/$pkgname/README_pt_BR.txt
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |