mangayomi
The pipx/uv/poetry/cargo/go/gem flag is a false positive; the PKGBUILD uses cargo and fvm/flutter for building the project's own source, which is normal and safe AUR packaging practice.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pipx/uv/poetry/cargo/go/gem flag is a false positive; the PKGBUILD uses cargo and fvm/flutter for building the project's own source, which is normal and safe AUR packaging practice.
1 higher static finding superseded - not the current verdict (shown for transparency)
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:36
cargo install 'flutter_rust_bridge_codegen'
PKGBUILD
1 offending line(s) highlighted# Maintainer: DeepChirp <deepchirp@archlinuxcn.org>
pkgname=mangayomi
pkgver=0.8.3
pkgrel=1
pkgdesc="free and open source application for reading manga, novels, and watching animes"
url="https://github.com/kodjodevf/${pkgname}"
license=('Apache-2.0')
arch=('x86_64')
depends=('gtk3' 'webkit2gtk-4.1' 'mpv' 'libsoup3' 'libepoxy' 'alsa-lib' 'hicolor-icon-theme' 'cairo' 'pango' 'at-spi2-core' 'fontconfig' 'glib2' 'glibc' 'libstdc++' 'libgcc')
makedepends=('cmake'
'ninja'
'clang'
'lld'
'fvm'
'rustup' # `Cargokit` expects to find `rustup`; otherwise, it will throw an error during the build process
'unzip'
'patchelf')
options=("!lto") # Due to differences in LLVM versions, errors occur when using LTO.
source=("${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/v${pkgver}.tar.gz")
sha256sums=('1c7a771ca085939c437357c8b3361f4da8823f57fb505d7f30954d5b763abac6')
prepare() {
cd "${pkgname}-${pkgver}"
export RUSTUP_HOME="${srcdir}/rustup-home"
export CARGO_HOME="${srcdir}/cargo-home"
export PATH="${CARGO_HOME}/bin:${PATH}"
rustup default stable
fvm use stable
fvm flutter --disable-analytics
fvm flutter pub get
cargo install 'flutter_rust_bridge_codegen'
cd rust
cargo fetch --locked --target "$CARCH-unknown-linux-gnu"
}
build() {
cd "${pkgname}-${pkgver}"
# use `gcc` will get error such as `Walloc-size-larger-than`
export CC=clang
export CXX=clang++
export RUSTUP_HOME="${srcdir}/rustup-home"
export CARGO_HOME="${srcdir}/cargo-home"
export PATH="${CARGO_HOME}/bin:${PATH}"
fvm flutter build linux --no-pub --release
}
package() {
cd "${pkgname}-${pkgver}"
install -dm755 "${pkgdir}/opt/${pkgname}"
cp -rd --no-preserve=ownership --preserve=mode build/linux/x64/release/bundle/* "${pkgdir}/opt/${pkgname}/"
install -dm755 "${pkgdir}/usr/bin"
ln -s "/opt/${pkgname}/${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
install -dm755 "${pkgdir}/usr/share/icons"
cp -rL --no-preserve=ownership --preserve=mode linux/packaging/icons/* "${pkgdir}/usr/share/icons/"
install -Dm644 "linux/${pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname}.desktop"
find "${pkgdir}/opt/${pkgname}/lib" -type f -name "*.so" -exec patchelf --set-rpath '$ORIGIN' {} \;
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |