matchplane-git
The 'bun install' runs on the project's own source from a fixed Git commit, posing no external code execution risk; the package builds from verified project-owned code, and the flagged pattern stems from static analysis ambiguity rather than actual supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The 'bun install' runs on the project's own source from a fixed Git commit, posing no external code execution risk; the package builds from verified project-owned code, and the flagged pattern stems from static analysis ambiguity rather than actual supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
bun_install_external
`bun add` / `bun install <package>` fetches an external package outside source=(). Severity downgraded: the package declares/looks like a Node.js consumer.
-
PKGBUILD:37
bun install --frozen-lockfile --cwd web
PKGBUILD
1 offending line(s) highlighted# Maintainer: LIghtJUNction <lightjunction.me@gmail.com>
pkgname=matchplane-git
# makepkg replaces this with the immutable checkout's workspace version and revision.
pkgver=0.1.10.r181.g7182c52
pkgrel=1
pkgdesc='Federated AI matching infrastructure (development version)'
arch=('x86_64')
url='https://github.com/LIghtJUNction/matchplane'
license=('MIT')
depends=('bubblewrap' 'ca-certificates' 'gcc-libs' 'git' 'glibc' 'nodejs>=22.12.0' 'openssl' 'zlib')
makedepends=('bun' 'cargo' 'cmake' 'curl' 'git' 'nodejs' 'protobuf' 'rust')
provides=('matchplane')
conflicts=('matchplane' 'matchplane-bin')
# makepkg's cross-language LTO drops native crypto symbols from SQLx's
# proc-macro shared object. Cargo still applies its safe per-crate optimizations.
options=('!lto')
backup=('etc/matchplane/matchplane.env')
install=matchplane.install
# The release workflow replaces 7182c52771249183a88d07343f861e8376c3ce70 with the exact GitHub commit being
# published. Keeping the VCS source immutable prevents a moving main branch from
# changing an AUR build after its review.
source=('matchplane::git+https://github.com/LIghtJUNction/matchplane.git#commit=7182c52771249183a88d07343f861e8376c3ce70')
sha256sums=('SKIP')
pkgver() {
cd matchplane
local base_version count revision
base_version=$(awk -F'"' '$1 ~ /^[[:space:]]*version[[:space:]]*=[[:space:]]*$/ { print $2; exit }' Cargo.toml)
[[ $base_version =~ ^[0-9]+\.[0-9]+\.[0-9]+([.][0-9]+)?$ ]] || return 1
count=$(git rev-list --count HEAD)
revision=$(git rev-parse --short=7 HEAD)
printf '%s.r%s.g%s' "$base_version" "$count" "$revision"
}
build() {
cd matchplane
bun install --frozen-lockfile --cwd web
bun run --cwd web build
cargo build --release --locked --workspace --bins
}
check() {
cd matchplane
bun run --cwd web test
cargo test --release --locked --workspace
}
package() {
cd matchplane
packaging/scripts/stage.sh "$pkgdir" target/release
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |