mingw-w64-cfitsio
maintainer Blaadick
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a standard tarball from the official project host (NASA's heasarc.gsfc.nasa.gov), building the project's own code; the non-whitelisted host is the project's legitimate release site, and the orphaned/re-adopted status does not indicate malice.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a standard tarball from the official project host (NASA's heasarc.gsfc.nasa.gov), building the project's own code; the non-whitelisted host is the project's legitimate release site, and the orphaned/re-adopted status does not indicate malice.
2 higher static findings superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source=(https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio-$pkgver.tar.gz)
MEDIUM
Recently orphaned & re-adopted
orphaned_readopted
This package was orphaned and re-adopted within the last 30 days — a window where ownership transfers can introduce malicious changes.
PKGBUILD
1 offending line(s) highlighted
1
pkgname=mingw-w64-cfitsio
2
pkgver=4.6.4
3
pkgrel=1
4
pkgdesc="A library of C and Fortran subroutines for reading and writing data files in FITS (Flexible Image Transport System) data format (mingw-w64)"
5
arch=("any")
6
url="https://heasarc.gsfc.nasa.gov/fitsio/"
7
license=("custom")
8
makedepends=("mingw-w64-cmake")
9
depends=("mingw-w64-zlib")
10
options=("!strip" "!buildflags" "staticlibs")
11
source=(https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio-$pkgver.tar.gz)
12
sha512sums=("18ad3b94cc2bc792b932d4bc9ddd1537d350597792bf31136a1a488cfa13d953060de5007aa986b4f295224c5f3579404a2a125ce065830da7ffaada40b4f62c")
13
14
_architectures="i686-w64-mingw32 x86_64-w64-mingw32"
15
16
build() {
17
cd cfitsio-${pkgver}
18
19
for _arch in ${_architectures}; do
20
mkdir -p build-${_arch} && pushd build-${_arch}
21
${_arch}-cmake -DUSE_CURL=OFF ..
22
make
23
popd
24
done
25
}
26
27
package() {
28
for _arch in ${_architectures}; do
29
cd "$srcdir/cfitsio-$pkgver/build-${_arch}"
30
make DESTDIR="${pkgdir}" install
31
${_arch}-strip --strip-unneeded "$pkgdir"/usr/${_arch}/bin/*.dll
32
${_arch}-strip -g "$pkgdir"/usr/${_arch}/lib/*.a
33
done
34
}
35
Changes since previous scan
--- PKGBUILD @ 2026-07-18 00:14+++ PKGBUILD @ 2026-08-03 00:08@@ -1,42 +1,35 @@-# Maintainer: CloverGit <clovergit@hotmail.com>-# Contributor: Michel Zou- pkgname=mingw-w64-cfitsio-pkgver=4.6.2+pkgver=4.6.4 pkgrel=1 pkgdesc="A library of C and Fortran subroutines for reading and writing data files in FITS (Flexible Image Transport System) data format (mingw-w64)"-arch=('any')+arch=("any") url="https://heasarc.gsfc.nasa.gov/fitsio/"-license=(custom)-makedepends=('mingw-w64-cmake')-depends=('mingw-w64-zlib')-options=('!strip' '!buildflags' 'staticlibs')+license=("custom")+makedepends=("mingw-w64-cmake")+depends=("mingw-w64-zlib")+options=("!strip" "!buildflags" "staticlibs") source=(https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio-$pkgver.tar.gz)-sha256sums=('66fd078cc0bea896b0d44b120d46d6805421a5361d3a5ad84d9f397b1b5de2cb')+sha512sums=("18ad3b94cc2bc792b932d4bc9ddd1537d350597792bf31136a1a488cfa13d953060de5007aa986b4f295224c5f3579404a2a125ce065830da7ffaada40b4f62c") _architectures="i686-w64-mingw32 x86_64-w64-mingw32" -prepare() {- cd cfitsio-${pkgver}-}+build() {+ cd cfitsio-${pkgver} -build() {- cd cfitsio-${pkgver}- for _arch in ${_architectures}; do- mkdir -p build-${_arch} && pushd build-${_arch}- ${_arch}-cmake -DUSE_CURL=OFF ..- make- popd- done+ for _arch in ${_architectures}; do+ mkdir -p build-${_arch} && pushd build-${_arch}+ ${_arch}-cmake -DUSE_CURL=OFF ..+ make+ popd+ done } package() {- for _arch in ${_architectures}; do- cd "$srcdir/cfitsio-$pkgver/build-${_arch}"- make DESTDIR="${pkgdir}" install- ${_arch}-strip --strip-unneeded "$pkgdir"/usr/${_arch}/bin/*.dll- ${_arch}-strip -g "$pkgdir"/usr/${_arch}/lib/*.a- done+ for _arch in ${_architectures}; do+ cd "$srcdir/cfitsio-$pkgver/build-${_arch}"+ make DESTDIR="${pkgdir}" install+ ${_arch}-strip --strip-unneeded "$pkgdir"/usr/${_arch}/bin/*.dll+ ${_arch}-strip -g "$pkgdir"/usr/${_arch}/lib/*.a+ done }-# vim: set sw=2 ts=2 et: Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 3 |
| 2026-08-02 00:16:08 | LOW | 3 |
| 2026-08-01 00:11:18 | LOW | 3 |
| 2026-07-31 00:14:10 | LOW | 3 |
| 2026-07-30 00:17:23 | LOW | 3 |
| 2026-07-29 00:25:53 | LOW | 3 |
| 2026-07-28 00:07:28 | LOW | 3 |
| 2026-07-27 00:24:32 | LOW | 3 |
| 2026-07-26 00:07:32 | LOW | 3 |
| 2026-07-25 00:13:44 | LOW | 3 |
| 2026-07-24 00:02:28 | LOW | 3 |
| 2026-07-23 00:14:47 | LOW | 3 |
| 2026-07-22 00:29:32 | LOW | 3 |
| 2026-07-21 00:24:15 | LOW | 3 |
| 2026-07-20 00:19:49 | LOW | 3 |
| 2026-07-19 00:17:08 | LOW | 3 |
| 2026-07-18 13:57:59 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | LOW | 3 |
| 2026-07-17 00:06:16 | LOW | 3 |
| 2026-07-16 03:50:18 | MEDIUM | 2 |