mingw-w64-duktape

maintainer annikkitikkanen · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is downloaded from the official project domain (duktape.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own site, not a third-party or personal hosting service.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the official project domain (duktape.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own site, not a third-party or personal hosting service.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("http://duktape.org/duktape-${pkgver}.tar.xz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Dario Ostuni <another.code.996@gmail.com>
2_pkgname=duktape
3pkgname=mingw-w64-${_pkgname}
4pkgver=2.3.0
5_dirname=${_pkgname}-${pkgver}
6pkgrel=1
7pkgdesc="Embeddable Javascript engine"
8arch=('any')
9url="http://duktape.org/"
10license=("MIT")
11makedepends=('mingw-w64-gcc')
12depends=('mingw-w64-crt')
13options=(staticlibs !strip !buildflags)
14source=("http://duktape.org/duktape-${pkgver}.tar.xz")
15sha384sums=('6200897d818a193ec346d357746c6d328bf16b6c763266830dc86c15c75a46cff71c3135b1a856b389eca9a4daa77df6')
16
17_architectures="i686-w64-mingw32 x86_64-w64-mingw32"
18
19build() {
20 for _arch in ${_architectures}; do
21 mkdir -p "${srcdir}/${pkgname}-${pkgver}-build-${_arch}"
22 pushd "${srcdir}/${_dirname}" > /dev/null
23 ${_arch}-gcc src/duktape.c -std=c99 -O2 -c -o duktape.o
24 ${_arch}-ar rcs libduktape.a duktape.o
25 pushd "../${pkgname}-${pkgver}-build-${_arch}" > /dev/null
26 mv "${srcdir}/${_dirname}/libduktape.a" "libduktape.a"
27 rm "${srcdir}/${_dirname}/duktape.o"
28 popd > /dev/null
29 popd > /dev/null
30 done
31}
32
33package() {
34 for _arch in ${_architectures}; do
35 pushd "${srcdir}/${pkgname}-${pkgver}-build-${_arch}" > /dev/null
36 install -Dm644 "libduktape.a" "$pkgdir/usr/${_arch}/lib/libduktape.a"
37 install -Dm644 "${srcdir}/${_dirname}/src/duk_config.h" "$pkgdir/usr/${_arch}/include/duk_config.h"
38 install -Dm644 "${srcdir}/${_dirname}/src/duktape.h" "$pkgdir/usr/${_arch}/include/duktape.h"
39 find "$pkgdir/usr/${_arch}" -name '*.exe' | xargs -rtl1 rm
40 find "$pkgdir/usr/${_arch}" -name '*.dll' | xargs -rtl1 ${_arch}-strip --strip-unneeded
41 find "$pkgdir/usr/${_arch}" -name '*.a' -o -name '*.dll' | xargs -rtl1 ${_arch}-strip -g
42 rm -rf "$pkgdir/usr/${_arch}/share"
43 popd > /dev/null
44 done
45}
46

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion