libjxl-metrics

maintainer damian101 · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source uses git clones from GitHub and Google's skia.googlesource.com, which are legitimate project repositories; the non-standard host flag for skia.googlesource.com is a false positive as it is an official upstream source, and the build uses verified commits with SKIP'd checksums due to VCS sources, which is standard for AUR packages.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source uses git clones from GitHub and Google's skia.googlesource.com, which are legitimate project repositories; the non-standard host flag for skia.googlesource.com is a false positive as it is an official upstream source, and the build uses verified commits with SKIP'd checksums due to VCS sources, which is standard for AUR packages.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:53 git+https://skia.googlesource.com/skcms.git#commit=96d9171c94b937a1b5f0293de7309ac16311b722

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Damian Höster <damian.hoester@posteo.de>
2# Contributor: Joshua Holmer <jholmer.in@gmail.com>
3
4_pkgname=libjxl
5pkgname=$_pkgname-metrics
6pkgver=0.12.0
7pkgrel=4
8pkgdesc='JPEG XL image format reference implementation with butteraugli, ssimulacra, and ssimulacra2 metrics'
9arch=(x86_64)
10url=https://jpeg.org/jpegxl/
11license=(BSD-3-Clause)
12depends=(
13 brotli
14 highway
15 libpng
16 libjpeg.so
17 giflib
18 openexr
19 gperftools
20)
21makedepends=(
22 git
23 cmake
24 clang
25 lld
26 python
27 asciidoc
28 # plugins disabled for now because https://github.com/libjxl/libjxl/issues/4037
29 #gdk-pixbuf2 # for building gdk-pixbuf loader
30 #gimp # for building GIMP plugin
31 #java-environment # for building JNI bindings
32)
33provides=(
34 $_pkgname
35 libjxl.so=0.12
36 libjxl_cms.so=0.12
37 libjxl_threads.so=0.12
38 butteraugli
39 ssimulacra
40 ssimulacra2
41)
42conflicts=(
43 $_pkgname
44 butteraugli
45 ssimulacra
46 ssimulacra2
47)
48optdepends=(
49 'libjxl-doc: for documentation'
50)
51source=(
52 git+https://github.com/libjxl/$_pkgname.git#tag=v$pkgver
53 git+https://skia.googlesource.com/skcms.git#commit=96d9171c94b937a1b5f0293de7309ac16311b722
54 git+https://github.com/webmproject/sjpeg.git#commit=94e0df6d0f8b44228de5be0ff35efb9f946a13c9
55)
56sha256sums=(
57 SKIP
58 SKIP
59 SKIP
60)
61
62prepare() {
63 git -C $_pkgname submodule init third_party/{skcms,sjpeg}
64 git -C $_pkgname config submodule.third_party/skcms.url "$srcdir"/skcms
65 git -C $_pkgname config submodule.third_party/sjpeg.url "$srcdir"/sjpeg
66 git -C $_pkgname -c protocol.file.allow=always submodule update
67}
68
69build() {
70 export CC=clang CXX=clang++
71 export LDFLAGS+=' -fuse-ld=lld'
72 cmake -S $_pkgname -B build --fresh \
73 -DBUILD_TESTING=OFF \
74 -DCMAKE_INSTALL_PREFIX=/usr \
75 -DJPEGXL_ENABLE_DEVTOOLS=ON \
76 -DJPEGXL_ENABLE_DOXYGEN=OFF \
77 -DJPEGXL_ENABLE_EXAMPLES=OFF \
78 -DJPEGXL_ENABLE_PLUGINS=OFF \
79 -DJPEGXL_FORCE_SYSTEM_BROTLI=ON \
80 -DJPEGXL_FORCE_SYSTEM_HWY=ON
81 make -C build
82}
83
84package() {
85 DESTDIR="$pkgdir" make -C build install
86 install -Dm644 $_pkgname/{LICENSE,PATENTS} \
87 -t "$pkgdir"/usr/share/licenses/$pkgname
88 ln -s /usr/bin/butteraugli_main "$pkgdir"/usr/bin/butteraugli
89 ln -s /usr/bin/ssimulacra_main "$pkgdir"/usr/bin/ssimulacra
90}
91

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 19:49:33 MEDIUM 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion