lexis-git
The package builds from a legitimate project source via git and uses pip to install only the project's own editable package and required build tools (pyinstaller), posing no supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds from a legitimate project source via git and uses pip to install only the project's own editable package and required build tools (pyinstaller), posing no supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:30
pip install --upgrade pip -
PKGBUILD:32
pip install pyinstaller
PKGBUILD
2 offending line(s) highlighted# Maintainer: Adınız <email@adresiniz.com>
pkgname=lexis-git
pkgver=r1.gf406063
pkgrel=1
pkgdesc="Yabancı dil öğrenenler için yapay zeka destekli, modern masaüstü sözlük uygulaması"
arch=('x86_64' 'aarch64')
url="https://github.com/talhacaglar/Lexis"
license=('MIT')
depends=('glibc' 'zlib' 'libx11' 'libxcb' 'libxkbcommon' 'fontconfig' 'freetype2' 'dbus')
makedepends=('git' 'python' 'python-pip' 'python-setuptools')
provides=("${pkgname%-git}")
conflicts=("${pkgname%-git}")
source=("lexis::git+https://github.com/talhacaglar/lexis.git"
"lexis.desktop")
md5sums=('SKIP'
'SKIP')
pkgver() {
cd "$srcdir/lexis"
printf "r%s.g%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
}
build() {
cd "$srcdir/lexis"
# PyInstaller kullanarak temiz ortamda derle
python -m venv .venv
source .venv/bin/activate
pip install --upgrade pip
pip install -e .
pip install pyinstaller
pyinstaller --name="lexis" \
--windowed \
--onedir \
--noconfirm \
--hidden-import="lexis.ui.views" \
--hidden-import="lexis.ui.widgets" \
--hidden-import="lexis.workers" \
--clean \
lexis/main.py
}
package() {
cd "$srcdir/lexis"
# Derlenen pyinstaller çıktılarını /opt/lexis içine atıyoruz
install -dm755 "$pkgdir/opt/lexis"
cp -r dist/lexis/* "$pkgdir/opt/lexis/"
# Sembolik link (terminalden direkt çalışması için)
install -dm755 "$pkgdir/usr/bin"
ln -s /opt/lexis/lexis "$pkgdir/usr/bin/lexis"
# Desktop file
install -Dm644 "$srcdir/lexis.desktop" "$pkgdir/usr/share/applications/lexis.desktop"
# SVG icon
if [ -f "packaging/icons/lexis.svg" ]; then
install -Dm644 "packaging/icons/lexis.svg" "$pkgdir/usr/share/icons/hicolor/scalable/apps/lexis.svg"
fi
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |