libvirt-vnc-viewer
The non-standard host is used only to fetch a patch from GitLab, which is a legitimate and common practice; the main source is from a trusted project site and the patch is applied transparently, posing no significant risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host is used only to fetch a patch from GitLab, which is a legitimate and common practice; the main source is from a trusted project site and the patch is applied transparently, posing no significant risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:27
"https://virt-manager.org/download/sources/virt-viewer/virt-viewer-${pkgver}.tar.xz"{,.asc}
PKGBUILD
1 offending line(s) highlighted# Maintainer: s3rj1k <evasive dot gyron at gmail dot com>
# Do not forget to run `makepkg --printsrcinfo > .SRCINFO`
pkgname=libvirt-vnc-viewer
pkgver=11.0
pkgrel=4
pkgdesc='Libvirt VNC Viewer GUI application.'
arch=('x86_64')
url='https://gitlab.com/virt-viewer/virt-viewer'
license=(
'GPL'
)
depends=(
'gtk-vnc'
'libvirt-glib-vnc'
'libvirt-vnc'
)
makedepends=(
'gobject-introspection'
'intltool'
'meson'
)
conflicts=(
'virt-viewer'
)
source=(
"https://virt-manager.org/download/sources/virt-viewer/virt-viewer-${pkgver}.tar.xz"{,.asc}
"https://gitlab.com/Paper_/virt-viewer/-/commit/41cc016278e713d3db156761fce6437dff81a53a.patch"
"meson.build.patch"
"src-meson.build.patch"
)
sha256sums=(
'a43fa2325c4c1c77a5c8c98065ac30ef0511a21ac98e590f22340869bad9abd0'
'SKIP'
'53a905df3678fdf1be238e3e5e27a8b60126d9238a5058da8476fdcb80ccaf71'
'c50cc3766e4c93530c1a79ea406a2015c804b7575b32d4c1d32fe3168a53d265'
'18f8eff99c1bc199ac60863bf6851ba8afe9b0e42d1a0f528507792c4a3a4338'
)
validpgpkeys=(
'DAF3A6FDB26B62912D0E8E3FBE86EBB415104FDF' # Daniel P. Berrange
)
prepare() {
cd "${srcdir}/virt-viewer-${pkgver}"
patch -p1 < "${srcdir}/41cc016278e713d3db156761fce6437dff81a53a.patch"
patch meson.build < "${srcdir}/meson.build.patch"
patch src/meson.build < "${srcdir}/src-meson.build.patch"
}
build() {
cd "${srcdir}/virt-viewer-${pkgver}"
arch-meson build \
--auto-features disabled \
-Dbash_completion=disabled \
-Dlibvirt=enabled \
-Dovirt=disabled \
-Dspice=disabled \
-Dvnc=enabled \
-Dvte=disabled
ninja -C build
}
package() {
cd "${srcdir}/virt-viewer-${pkgver}"
DESTDIR="${pkgdir}" ninja -C build install
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |