karamel-git
maintainer orphaned
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The PKGBUILD uses opam to install OCaml dependencies and build the project from its official Git repositories; this is a normal build process for OCaml software, not an external install of untrusted code.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The PKGBUILD uses opam to install OCaml dependencies and build the project from its official Git repositories; this is a normal build process for OCaml software, not an external install of untrusted code.
2 higher static findings superseded - not the current verdict (shown for transparency)
MEDIUM
External install via pipx/uv/poetry/cargo/go/gem
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:41
CHECK_IF_PREINSTALLED=false opam install --yes --no-depexts conf-python-2-7 ppx_deriving_yojson zarith pprint "menhir>=20161115" sedlex process fix "wasm>=2.0.0" visitors ctypes-foreign ctypes
MEDIUM
Recently orphaned & re-adopted
orphaned_readopted
This package was orphaned and re-adopted within the last 30 days — a window where ownership transfers can introduce malicious changes.
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: crave <crave@infinity>
2
3
pkgname=karamel-git
4
pkgver=fstar.v2022.11.19.r846.g71facac.karamel.v1.0.0.r421.gbd359d8
5
pkgrel=1
6
pkgdesc="a tool for extracting low-level F* programs to readable C code"
7
arch=('i686' 'x86_64')
8
url='https://github.com/FStarLang/karamel'
9
license=('Apache-2.0')
10
options=('!strip' '!makeflags' 'staticlibs')
11
depends=('python2' 'opam' 'which')
12
conflicts=('fstar')
13
source=('git+https://github.com/FStarLang/FStar.git'
14
'git+https://github.com/FStarLang/karamel.git')
15
sha256sums=('SKIP' 'SKIP')
16
17
pkgver() {
18
(cd FStar
19
echo -n 'fstar.'
20
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g' | tr -d '\n')
21
(cd karamel
22
echo -n '.karamel.'
23
git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g')
24
}
25
26
OPAM_VER=4.11.0
27
build() {
28
cd "$srcdir"
29
export FSTAR_HOME="$(realpath FStar)"
30
export PATH="$FSTAR_HOME/bin:$PATH"
31
32
if ! [ -d ~/.opam ]; then
33
# I know you probably shouldn't do this in a PKGBUILD
34
# But I don't care about ocaml, I just want to use this software
35
opam init --shell-setup
36
opam switch create "$OPAM_VER"
37
opam switch "$OPAM_VER"
38
fi
39
40
(eval $(opam env)
41
CHECK_IF_PREINSTALLED=false opam install --yes --no-depexts conf-python-2-7 ppx_deriving_yojson zarith pprint "menhir>=20161115" sedlex process fix "wasm>=2.0.0" visitors ctypes-foreign ctypes
42
(cd FStar
43
opam install --yes --deps-only .
44
make -j$(nproc))
45
(cd karamel
46
make -j$(nproc))) || echo "If the build failed because of some ocaml messages try deleting ~/.opam, and re-run"
47
}
48
49
package() {
50
eval $(opam env)
51
cd "$srcdir"
52
export PREFIX="$pkgdir/opt/fstar"
53
mkdir -p "$PREFIX"
54
#(cd FStar; make -j$(nproc) install; cd ulib; export INSTALL_EXEC="$(which install)"; ./install-ulib.sh)
55
cp -r FStar/* $PREFIX
56
export FSTAR_HOME="$PREFIX"
57
58
export PREFIX="$pkgdir/opt/karamel"
59
#(cd karamel; make -j$(nproc) install)
60
mkdir -p "$PREFIX"
61
cp -r karamel/* $PREFIX
62
}
63
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 3 |
| 2026-08-02 00:16:08 | LOW | 3 |
| 2026-08-01 00:11:18 | LOW | 3 |
| 2026-07-31 00:14:10 | LOW | 3 |
| 2026-07-30 00:17:23 | LOW | 3 |
| 2026-07-29 00:25:53 | LOW | 3 |
| 2026-07-28 00:07:28 | LOW | 3 |
| 2026-07-27 00:24:32 | LOW | 3 |
| 2026-07-26 00:07:32 | LOW | 3 |
| 2026-07-25 00:13:44 | LOW | 3 |
| 2026-07-24 00:02:28 | LOW | 3 |
| 2026-07-23 00:14:47 | LOW | 3 |
| 2026-07-22 00:29:32 | LOW | 3 |
| 2026-07-21 00:24:15 | LOW | 3 |
| 2026-07-20 01:12:32 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | LOW | 3 |
| 2026-07-19 00:17:08 | LOW | 3 |
| 2026-07-18 00:14:48 | LOW | 3 |
| 2026-07-17 00:06:16 | LOW | 3 |
| 2026-07-16 00:05:41 | LOW | 3 |