lsr-iouring-git
The source is a git repository from a personal domain, but it is the project's own upstream source being built from scratch using Zig, which is a normal AUR packaging practice; the non-standard host is plausibly legitimate for a niche project, and there is no execution of prebuilt binaries or malicious payloads.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a git repository from a personal domain, but it is the project's own upstream source being built from scratch using Zig, which is a normal AUR packaging practice; the non-standard host is plausibly legitimate for a niche project, and there is no execution of prebuilt binaries or malicious payloads.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=('git+https://tangled.sh/@rockorager.dev/lsr')
PKGBUILD
1 offending line(s) highlighted# Maintainer: c4
pkgname=lsr-iouring-git
_pkgname=lsr
pkgver=1.0.0.r1.g0c4dc41
pkgrel=2
pkgdesc="ls but with io_uring"
arch=('x86_64')
url="https://tangled.sh/@rockorager.dev/lsr"
license=('MIT')
makedepends=('zig' 'git')
optdepends=(
'anyzig: lets you run any version of zig'
)
_pkgsrc="$_pkgname"
source=('git+https://tangled.sh/@rockorager.dev/lsr')
sha256sums=('SKIP')
prepare() {
cd "$_pkgsrc"
# PACKAGING.md -> build.zig.zon
# fetch to host system $( zig env | jq .global_cache_dir | tr -d '"' ) or the default "$HOME/.cache/zig"
# ln -s $( zig env | jq .global_cache_dir | tr -d '"' ) "$srcdir/zig-global-cache"
# for i in $(grep '\.url' build.zig.zon | sed -E 's&^.* = "(\S+)".*$&\1&'); do
# zig fetch --global-cache-dir $( zig env | jq .global_cache_dir | tr -d '"' ) "$i"
# done
export ZIG_GLOBAL_CACHE_DIR="$srcdir/zig-global-cache/"
zig build --fetch
}
pkgver() {
cd "$_pkgsrc"
local _tag=$(git tag | sort -rV | head -1)
local _version"=${_tag#v}"
local _revision=$(git rev-list --count --cherry-pick "$_tag"...HEAD)
local _hash=$(git rev-parse --short=7 HEAD)
printf '%s.r%s.g%s' "${_version:?}" "${_revision:?}" "${_hash:?}"
}
build() {
local _zig_options=(
--summary all
--prefix /usr
--search-prefix /usr
--global-cache-dir "$srcdir/zig-global-cache"
--system "$srcdir/zig-global-cache/p"
-Dtarget=native-native-gnu
-Dcpu=native
-Doptimize=ReleaseSmall
)
cd "$_pkgsrc"
DESTDIR="build" zig build "${_zig_options[@]}"
}
package() {
cd "$_pkgsrc"
cp --reflink=auto -a build/* "$pkgdir"
install -Dm644 LICENSE ${pkgdir}/usr/share/licenses/${pkgname}/LICENSE
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |