libvirt-vnc-viewer
maintainer orphaned
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The non-standard host is used only to fetch a patch from GitLab, which is a legitimate and common practice; the main source is from a trusted project site and the patch is applied transparently, posing no significant risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host is used only to fetch a patch from GitLab, which is a legitimate and common practice; the main source is from a trusted project site and the patch is applied transparently, posing no significant risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:27
"https://virt-manager.org/download/sources/virt-viewer/virt-viewer-${pkgver}.tar.xz"{,.asc}
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: s3rj1k <evasive dot gyron at gmail dot com>
2
# Do not forget to run `makepkg --printsrcinfo > .SRCINFO`
3
4
pkgname=libvirt-vnc-viewer
5
pkgver=11.0
6
pkgrel=4
7
pkgdesc='Libvirt VNC Viewer GUI application.'
8
arch=('x86_64')
9
url='https://gitlab.com/virt-viewer/virt-viewer'
10
license=(
11
'GPL'
12
)
13
depends=(
14
'gtk-vnc'
15
'libvirt-glib-vnc'
16
'libvirt-vnc'
17
)
18
makedepends=(
19
'gobject-introspection'
20
'intltool'
21
'meson'
22
)
23
conflicts=(
24
'virt-viewer'
25
)
26
source=(
27
"https://virt-manager.org/download/sources/virt-viewer/virt-viewer-${pkgver}.tar.xz"{,.asc}
28
"https://gitlab.com/Paper_/virt-viewer/-/commit/41cc016278e713d3db156761fce6437dff81a53a.patch"
29
"meson.build.patch"
30
"src-meson.build.patch"
31
)
32
sha256sums=(
33
'a43fa2325c4c1c77a5c8c98065ac30ef0511a21ac98e590f22340869bad9abd0'
34
'SKIP'
35
'53a905df3678fdf1be238e3e5e27a8b60126d9238a5058da8476fdcb80ccaf71'
36
'c50cc3766e4c93530c1a79ea406a2015c804b7575b32d4c1d32fe3168a53d265'
37
'18f8eff99c1bc199ac60863bf6851ba8afe9b0e42d1a0f528507792c4a3a4338'
38
)
39
validpgpkeys=(
40
'DAF3A6FDB26B62912D0E8E3FBE86EBB415104FDF' # Daniel P. Berrange
41
)
42
43
prepare() {
44
cd "${srcdir}/virt-viewer-${pkgver}"
45
patch -p1 < "${srcdir}/41cc016278e713d3db156761fce6437dff81a53a.patch"
46
patch meson.build < "${srcdir}/meson.build.patch"
47
patch src/meson.build < "${srcdir}/src-meson.build.patch"
48
}
49
50
build() {
51
cd "${srcdir}/virt-viewer-${pkgver}"
52
53
arch-meson build \
54
--auto-features disabled \
55
-Dbash_completion=disabled \
56
-Dlibvirt=enabled \
57
-Dovirt=disabled \
58
-Dspice=disabled \
59
-Dvnc=enabled \
60
-Dvte=disabled
61
62
ninja -C build
63
}
64
65
package() {
66
cd "${srcdir}/virt-viewer-${pkgver}"
67
68
DESTDIR="${pkgdir}" ninja -C build install
69
}
70
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |