mingw-w64-duktape
maintainer annikkitikkanen
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is downloaded from the official project domain (duktape.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own site, not a third-party or personal hosting service.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the official project domain (duktape.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own site, not a third-party or personal hosting service.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("http://duktape.org/duktape-${pkgver}.tar.xz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Dario Ostuni <another.code.996@gmail.com>
2
_pkgname=duktape
3
pkgname=mingw-w64-${_pkgname}
4
pkgver=2.3.0
5
_dirname=${_pkgname}-${pkgver}
6
pkgrel=1
7
pkgdesc="Embeddable Javascript engine"
8
arch=('any')
9
url="http://duktape.org/"
10
license=("MIT")
11
makedepends=('mingw-w64-gcc')
12
depends=('mingw-w64-crt')
13
options=(staticlibs !strip !buildflags)
14
source=("http://duktape.org/duktape-${pkgver}.tar.xz")
15
sha384sums=('6200897d818a193ec346d357746c6d328bf16b6c763266830dc86c15c75a46cff71c3135b1a856b389eca9a4daa77df6')
16
17
_architectures="i686-w64-mingw32 x86_64-w64-mingw32"
18
19
build() {
20
for _arch in ${_architectures}; do
21
mkdir -p "${srcdir}/${pkgname}-${pkgver}-build-${_arch}"
22
pushd "${srcdir}/${_dirname}" > /dev/null
23
${_arch}-gcc src/duktape.c -std=c99 -O2 -c -o duktape.o
24
${_arch}-ar rcs libduktape.a duktape.o
25
pushd "../${pkgname}-${pkgver}-build-${_arch}" > /dev/null
26
mv "${srcdir}/${_dirname}/libduktape.a" "libduktape.a"
27
rm "${srcdir}/${_dirname}/duktape.o"
28
popd > /dev/null
29
popd > /dev/null
30
done
31
}
32
33
package() {
34
for _arch in ${_architectures}; do
35
pushd "${srcdir}/${pkgname}-${pkgver}-build-${_arch}" > /dev/null
36
install -Dm644 "libduktape.a" "$pkgdir/usr/${_arch}/lib/libduktape.a"
37
install -Dm644 "${srcdir}/${_dirname}/src/duk_config.h" "$pkgdir/usr/${_arch}/include/duk_config.h"
38
install -Dm644 "${srcdir}/${_dirname}/src/duktape.h" "$pkgdir/usr/${_arch}/include/duktape.h"
39
find "$pkgdir/usr/${_arch}" -name '*.exe' | xargs -rtl1 rm
40
find "$pkgdir/usr/${_arch}" -name '*.dll' | xargs -rtl1 ${_arch}-strip --strip-unneeded
41
find "$pkgdir/usr/${_arch}" -name '*.a' -o -name '*.dll' | xargs -rtl1 ${_arch}-strip -g
42
rm -rf "$pkgdir/usr/${_arch}/share"
43
popd > /dev/null
44
done
45
}
46
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |