lib32-sdl_sound
The source is downloaded from the project's official domain (icculus.org), which is plausibly the project's own hosting; building from official project sources is normal AUR packaging, even if the host is not on a standard whitelist.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the project's official domain (icculus.org), which is plausibly the project's own hosting; building from official project sources is normal AUR packaging, even if the host is not on a standard whitelist.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=("http://icculus.org/SDL_sound/downloads/SDL_sound-$pkgver.tar.gz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: envolution
# Contributor: carstene1ns <arch carsten-teibes de> - http://git.io/ctPKG
# Contributor: trya <tryagainprod@gmail.com>
# Contributor: Jan Alexander Steffens (heftig) <jan.steffens@gmail.com>
# Contributor: Tom Newsom <Jeepster@gmx.co.uk>
# shellcheck shell=bash disable=SC2034,SC2154
pkgname=lib32-sdl_sound
pkgver=1.0.3
pkgrel=8
epoch=1
pkgdesc="A library to decode several popular sound file formats, such as .WAV and .MP3 (32 bit)"
arch=('x86_64')
url="http://icculus.org/SDL_sound/"
license=('LGPL')
depends=('lib32-sdl' 'lib32-libmikmod' 'libvorbis' 'lib32-flac' 'lib32-speex' 'lib32-smpeg'
'lib32-libmodplug' 'sdl_sound')
conflicts=(lib32-sdl12-compat) #this does not provide /usr/bin/sdl-config-32
source=("http://icculus.org/SDL_sound/downloads/SDL_sound-$pkgver.tar.gz")
sha256sums=('3999fd0bbb485289a52be14b2f68b571cb84e380cc43387eadf778f64c79e6df')
prepare() {
# renamed since physfs 2.1.1
sed 's/__EXPORT__/PHYSFS_DECL/g' -i SDL_sound-$pkgver/playsound/physfsrwops.h
}
build() {
cd SDL_sound-$pkgver
export CC="gcc -m32"
export CXX="g++ -m32"
export PKG_CONFIG_PATH="/usr/lib32/pkgconfig"
export SDL_CONFIG=/usr/bin/sdl-config-32
export CPPFLAGS="$CPPFLAGS -I/usr/include/smpeg"
./configure --prefix=/usr --libdir=/usr/lib32 --with-sdl-prefix=/usr/lib32 --disable-static
make
}
package() {
cd SDL_sound-$pkgver
make DESTDIR="$pkgdir" install
# remove stuff already present in sdl_sound package
rm -rf "$pkgdir"/usr/{bin,include}
}
# vim:set ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |