mangayomi

LOW
maintainer DeepChirp 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The pipx/uv/poetry/cargo/go/gem flag is a false positive; the PKGBUILD uses cargo and fvm/flutter for building the project's own source, which is normal and safe AUR packaging practice.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pipx/uv/poetry/cargo/go/gem flag is a false positive; the PKGBUILD uses cargo and fvm/flutter for building the project's own source, which is normal and safe AUR packaging practice.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium External install via pipx/uv/poetry/cargo/go/gem alt_pkg_manager_install

A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:36 cargo install 'flutter_rust_bridge_codegen'

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: DeepChirp <deepchirp@archlinuxcn.org>
2
3pkgname=mangayomi
4pkgver=0.8.3
5pkgrel=1
6pkgdesc="free and open source application for reading manga, novels, and watching animes"
7url="https://github.com/kodjodevf/${pkgname}"
8license=('Apache-2.0')
9arch=('x86_64')
10depends=('gtk3' 'webkit2gtk-4.1' 'mpv' 'libsoup3' 'libepoxy' 'alsa-lib' 'hicolor-icon-theme' 'cairo' 'pango' 'at-spi2-core' 'fontconfig' 'glib2' 'glibc' 'libstdc++' 'libgcc')
11makedepends=('cmake'
12 'ninja'
13 'clang'
14 'lld'
15 'fvm'
16 'rustup' # `Cargokit` expects to find `rustup`; otherwise, it will throw an error during the build process
17 'unzip'
18 'patchelf')
19options=("!lto") # Due to differences in LLVM versions, errors occur when using LTO.
20source=("${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/v${pkgver}.tar.gz")
21sha256sums=('1c7a771ca085939c437357c8b3361f4da8823f57fb505d7f30954d5b763abac6')
22
23prepare() {
24 cd "${pkgname}-${pkgver}"
25
26 export RUSTUP_HOME="${srcdir}/rustup-home"
27 export CARGO_HOME="${srcdir}/cargo-home"
28 export PATH="${CARGO_HOME}/bin:${PATH}"
29
30 rustup default stable
31
32 fvm use stable
33 fvm flutter --disable-analytics
34 fvm flutter pub get
35
36 cargo install 'flutter_rust_bridge_codegen'
37
38 cd rust
39 cargo fetch --locked --target "$CARCH-unknown-linux-gnu"
40}
41
42build() {
43 cd "${pkgname}-${pkgver}"
44
45 # use `gcc` will get error such as `Walloc-size-larger-than`
46 export CC=clang
47 export CXX=clang++
48
49 export RUSTUP_HOME="${srcdir}/rustup-home"
50 export CARGO_HOME="${srcdir}/cargo-home"
51 export PATH="${CARGO_HOME}/bin:${PATH}"
52
53 fvm flutter build linux --no-pub --release
54}
55
56package() {
57 cd "${pkgname}-${pkgver}"
58
59 install -dm755 "${pkgdir}/opt/${pkgname}"
60 cp -rd --no-preserve=ownership --preserve=mode build/linux/x64/release/bundle/* "${pkgdir}/opt/${pkgname}/"
61
62 install -dm755 "${pkgdir}/usr/bin"
63 ln -s "/opt/${pkgname}/${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
64
65 install -dm755 "${pkgdir}/usr/share/icons"
66 cp -rL --no-preserve=ownership --preserve=mode linux/packaging/icons/* "${pkgdir}/usr/share/icons/"
67
68 install -Dm644 "linux/${pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname}.desktop"
69
70 find "${pkgdir}/opt/${pkgname}/lib" -type f -name "*.so" -exec patchelf --set-rpath '$ORIGIN' {} \;
71}
72

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion