mamepgui
The source is a tarball from a personal server (et6.free.fr), which is not on a standard host whitelist, but it is a legitimate source for this project's own release tarball; the build process compiles from source and does not execute untrusted binaries, so the realistic worst case is limited to supply-chain risk from an unverifiable but plausibly project-owned source.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from a personal server (et6.free.fr), which is not on a standard host whitelist, but it is a legitimate source for this project's own release tarball; the build process compiles from source and does not execute untrusted binaries, so the realistic worst case is limited to supply-chain risk from an unverifiable but plausibly project-owned source.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("http://et6.free.fr/temp/mamepgui-1.6.0.tar.gz"
PKGBUILD
1 offending line(s) highlighted# Maintainer: trya <tryagainprod@gmail.com>
pkgname=mamepgui
pkgver=1.6.0
pkgrel=3
pkgdesc="Frontend for SDLMAME/SDLMESS based on MAME Plus!"
arch=('i686' 'x86_64')
url="http://sourceforge.net/projects/mameplus"
license=('custom:WTFPL')
depends=('qt4' 'quazip-qt4')
optdepends=('sdlmame: port of MAME/MESS using SDL')
source=("http://et6.free.fr/temp/mamepgui-1.6.0.tar.gz"
'COPYING')
md5sums=('df681ca55de544a726ea3019e069ed98'
'389a9e29629d1f05e115f8f05c283df5')
prepare() {
cd "$srcdir/$pkgname"
# disable static compilation and SDL 1.3 linking
sed -e 's|CONFIG += build_static|#CONFIG += build_static|' \
-e 's|CONFIG += build_sdl|#CONFIG += build_sdl|' \
-i common_settings.pri
# use included libraries instead of installed ones
sed -e 's|LIBS += -L./lib/$${OSDIR}|QMAKE_LIBDIR += ./lib/$${OSDIR}|' \
-e 's|LIBS += -lquazip -llzma|LIBS += -lquazip -llzma -lz|' \
-e 's|TARGETDEPS +=|#TARGETDEPS +=|' \
-e 's|./lib/$${OSDIR}/libquazip.a|#./lib/$${OSDIR}/libquazip.a|' \
-e 's|./lib/$${OSDIR}/liblzma.a|#./lib/$${OSDIR}/liblzma.a|' \
-i mamepgui.pro
}
build() {
cd "$srcdir/$pkgname"
# build included liblzma.a (system one is not compatible)
cd lzma
qmake-qt4
make
# build mamepgui
cd ..
lrelease-qt4 mamepgui.pro
qmake-qt4
make
}
package() {
cd "$srcdir/$pkgname"
# install license
install -Dm644 "$srcdir/COPYING" "$pkgdir/usr/share/licenses/$pkgname/COPYING"
# copy documentation
install -d "$pkgdir/usr/share/doc/mamepgui"
cp docs/* "$pkgdir/usr/share/doc/mamepgui"
# install executable
install -Dm755 bin/mamepgui "$pkgdir/usr/bin/mamepgui"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |