matchplane-git

LOW
maintainer lightjunction 0 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The 'bun install' runs on the project's own source from a fixed Git commit, posing no external code execution risk; the package builds from verified project-owned code, and the flagged pattern stems from static analysis ambiguity rather than actual supply-chain risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The 'bun install' runs on the project's own source from a fixed Git commit, posing no external code execution risk; the package builds from verified project-owned code, and the flagged pattern stems from static analysis ambiguity rather than actual supply-chain risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium bun install of an undeclared external package bun_install_external

`bun add` / `bun install <package>` fetches an external package outside source=(). Severity downgraded: the package declares/looks like a Node.js consumer.

  • PKGBUILD:37 bun install --frozen-lockfile --cwd web

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: LIghtJUNction <lightjunction.me@gmail.com>
2pkgname=matchplane-git
3# makepkg replaces this with the immutable checkout's workspace version and revision.
4pkgver=0.1.10.r181.g7182c52
5pkgrel=1
6pkgdesc='Federated AI matching infrastructure (development version)'
7arch=('x86_64')
8url='https://github.com/LIghtJUNction/matchplane'
9license=('MIT')
10depends=('bubblewrap' 'ca-certificates' 'gcc-libs' 'git' 'glibc' 'nodejs>=22.12.0' 'openssl' 'zlib')
11makedepends=('bun' 'cargo' 'cmake' 'curl' 'git' 'nodejs' 'protobuf' 'rust')
12provides=('matchplane')
13conflicts=('matchplane' 'matchplane-bin')
14# makepkg's cross-language LTO drops native crypto symbols from SQLx's
15# proc-macro shared object. Cargo still applies its safe per-crate optimizations.
16options=('!lto')
17backup=('etc/matchplane/matchplane.env')
18install=matchplane.install
19# The release workflow replaces 7182c52771249183a88d07343f861e8376c3ce70 with the exact GitHub commit being
20# published. Keeping the VCS source immutable prevents a moving main branch from
21# changing an AUR build after its review.
22source=('matchplane::git+https://github.com/LIghtJUNction/matchplane.git#commit=7182c52771249183a88d07343f861e8376c3ce70')
23sha256sums=('SKIP')
24
25pkgver() {
26 cd matchplane
27 local base_version count revision
28 base_version=$(awk -F'"' '$1 ~ /^[[:space:]]*version[[:space:]]*=[[:space:]]*$/ { print $2; exit }' Cargo.toml)
29 [[ $base_version =~ ^[0-9]+\.[0-9]+\.[0-9]+([.][0-9]+)?$ ]] || return 1
30 count=$(git rev-list --count HEAD)
31 revision=$(git rev-parse --short=7 HEAD)
32 printf '%s.r%s.g%s' "$base_version" "$count" "$revision"
33}
34
35build() {
36 cd matchplane
37 bun install --frozen-lockfile --cwd web
38 bun run --cwd web build
39 cargo build --release --locked --workspace --bins
40}
41
42check() {
43 cd matchplane
44 bun run --cwd web test
45 cargo test --release --locked --workspace
46}
47
48package() {
49 cd matchplane
50 packaging/scripts/stage.sh "$pkgdir" target/release
51}
52

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion