mangayomi

maintainer DeepChirp · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The pipx/uv/poetry/cargo/go/gem flag is a false positive; the PKGBUILD uses cargo install locally during build for flutter_rust_bridge_codegen, which is a legitimate build dependency, not an external install into the user environment.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pipx/uv/poetry/cargo/go/gem flag is a false positive; the PKGBUILD uses cargo install locally during build for flutter_rust_bridge_codegen, which is a legitimate build dependency, not an external install into the user environment.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM External install via pipx/uv/poetry/cargo/go/gem alt_pkg_manager_install

A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:36 cargo install 'flutter_rust_bridge_codegen'

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: DeepChirp <deepchirp@archlinuxcn.org>
2
3pkgname=mangayomi
4pkgver=0.8.1
5pkgrel=1
6pkgdesc="free and open source application for reading manga, novels, and watching animes"
7url="https://github.com/kodjodevf/${pkgname}"
8license=('Apache-2.0')
9arch=('x86_64')
10depends=('gtk3' 'webkit2gtk-4.1' 'mpv' 'libsoup3' 'libepoxy' 'alsa-lib' 'hicolor-icon-theme' 'cairo' 'pango' 'at-spi2-core' 'fontconfig' 'glib2' 'glibc' 'libstdc++' 'libgcc')
11makedepends=('cmake'
12 'ninja'
13 'clang'
14 'lld'
15 'fvm'
16 'rustup' # `Cargokit` expects to find `rustup`; otherwise, it will throw an error during the build process
17 'unzip'
18 'patchelf')
19options=("!lto") # Due to differences in LLVM versions, errors occur when using LTO.
20source=("${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/v${pkgver}.tar.gz")
21sha256sums=('fa957822fc787c6be22dc3065de6211d9e00829e2d36b89c38c5341c0a01c959')
22
23prepare() {
24 cd "${pkgname}-${pkgver}"
25
26 export RUSTUP_HOME="${srcdir}/rustup-home"
27 export CARGO_HOME="${srcdir}/cargo-home"
28 export PATH="${CARGO_HOME}/bin:${PATH}"
29
30 rustup default stable
31
32 fvm use stable
33 fvm flutter --disable-analytics
34 fvm flutter pub get
35
36 cargo install 'flutter_rust_bridge_codegen'
37
38 cd rust
39 cargo fetch --locked --target "$CARCH-unknown-linux-gnu"
40}
41
42build() {
43 cd "${pkgname}-${pkgver}"
44
45 # use `gcc` will get error such as `Walloc-size-larger-than`
46 export CC=clang
47 export CXX=clang++
48
49 export RUSTUP_HOME="${srcdir}/rustup-home"
50 export CARGO_HOME="${srcdir}/cargo-home"
51 export PATH="${CARGO_HOME}/bin:${PATH}"
52
53 fvm flutter build linux --no-pub --release
54}
55
56package() {
57 cd "${pkgname}-${pkgver}"
58
59 install -dm755 "${pkgdir}/opt/${pkgname}"
60 cp -rd --no-preserve=ownership --preserve=mode build/linux/x64/release/bundle/* "${pkgdir}/opt/${pkgname}/"
61
62 install -dm755 "${pkgdir}/usr/bin"
63 ln -s "/opt/${pkgname}/${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
64
65 install -dm755 "${pkgdir}/usr/share/icons"
66 cp -rL --no-preserve=ownership --preserve=mode linux/packaging/icons/* "${pkgdir}/usr/share/icons/"
67
68 install -Dm644 "linux/${pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname}.desktop"
69
70 find "${pkgdir}/opt/${pkgname}/lib" -type f -name "*.so" -exec patchelf --set-rpath '$ORIGIN' {} \;
71}
72

Changes since previous scan

--- PKGBUILD @ 2026-07-31 00:14
+++ PKGBUILD @ 2026-08-03 00:08
@@ -1,7 +1,7 @@
# Maintainer: DeepChirp <deepchirp@archlinuxcn.org>
pkgname=mangayomi
-pkgver=0.7.80
+pkgver=0.8.1
pkgrel=1
pkgdesc="free and open source application for reading manga, novels, and watching animes"
url="https://github.com/kodjodevf/${pkgname}"
@@ -18,7 +18,7 @@
'patchelf')
options=("!lto") # Due to differences in LLVM versions, errors occur when using LTO.
source=("${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/v${pkgver}.tar.gz")
-sha256sums=('9a3e404ce23b3219eba2d89a60477858473da24b34eb3fce5fc7b1f6d71e76a2')
+sha256sums=('fa957822fc787c6be22dc3065de6211d9e00829e2d36b89c38c5341c0a01c959')
prepare() {
cd "${pkgname}-${pkgver}"

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 21:18:45 MEDIUM 1
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion