mingw-w64-libgeotiff
The source is a standard tarball from the project's official download host (download.osgeo.org), which is a trusted domain for OSGeo projects; building from this source is normal and expected, despite the static analyzer flagging it as non-standard.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a standard tarball from the project's official download host (download.osgeo.org), which is a trusted domain for OSGeo projects; building from this source is normal and expected, despite the static analyzer flagging it as non-standard.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("http://download.osgeo.org/geotiff/libgeotiff/libgeotiff-${pkgver}.tar.gz"
PKGBUILD
1 offending line(s) highlighted# Contributor: Andrew Sun <adsun701 at gmail dot com>
pkgname=mingw-w64-libgeotiff
pkgver=1.7.1
pkgrel=1
pkgdesc="A TIFF based interchange format for georeferenced raster imagery (mingw-w64)"
arch=('any')
url="https://trac.osgeo.org/geotiff/"
license=('custom')
depends=('mingw-w64-libtiff' 'mingw-w64-proj' 'mingw-w64-libjpeg-turbo')
makedepends=('mingw-w64-configure')
options=('!buildflags' 'staticlibs' '!strip')
source=("http://download.osgeo.org/geotiff/libgeotiff/libgeotiff-${pkgver}.tar.gz"
"libgeotiff_buildsys.patch")
sha256sums=('05ab1347aaa471fc97347d8d4269ff0c00f30fa666d956baba37948ec87e55d6'
'fb7e213559f779905c913389ad715e3aaf849c0e8c8ef72df86d1ca313d9393b')
_architectures="i686-w64-mingw32 x86_64-w64-mingw32"
prepare() {
cd ${srcdir}/libgeotiff-${pkgver}
patch -p1 -i ../libgeotiff_buildsys.patch
# fix wrongly encoded files from tarball
for f in $(find . -type f); do
if file $f | grep -q ISO-8859 ; then
iconv -f ISO-8859-1 -t UTF-8 $f > ${f}.tmp && \
mv -f ${f}.tmp $f
fi
if file $f | grep -q CRLF ; then
sed -i -e 's|\r$||g' $f
fi
done
./autogen.sh
}
build() {
cd ${srcdir}/libgeotiff-${pkgver}
for _arch in ${_architectures}; do
mkdir -p build-${_arch} && pushd build-${_arch}
${_arch}-configure \
--with-proj \
--with-jpeg \
--with-zip \
..
# FIXME: out-of-source build fails
# cp ../*.h libxtiff
# cp ../libxtiff/*.h libxtiff
# cp ../*.inc bin
# ${_arch}-cmake -DCMAKE_BUILD_TYPE=Release \
# -DGEOTIFF_CSV_DATA_DIR=$PWD/../csv \
# -DGEOTIFF_DATA_SUBDIR=share \
# -DGEOTIFF_BIN_SUBDIR=bin \
# ..
make
popd
done
}
package() {
for _arch in ${_architectures}; do
cd "${srcdir}/libgeotiff-${pkgver}/build-${_arch}"
make DESTDIR="${pkgdir}" install
mkdir -p "${pkgdir}"/usr/${_arch}/lib/pkgconfig/
cat > ${pkgdir}/usr/${_arch}/lib/pkgconfig/libgeotiff.pc <<EOF
prefix=/usr/${_arch}
exec_prefix=\${prefix}
libdir=\${prefix}/lib
includedir=\${prefix}/include
Name: libgeotiff
Description: GeoTIFF file format library
Version: ${pkgver}
Libs: -L\${libdir} -lgeotiff
Cflags: -I\${includedir}
EOF
rm -rf "${pkgdir}"/usr/${_arch}/share
find "${pkgdir}/usr/${_arch}" -name '*.def' -o -name '*.exp' | xargs -rtl1 rm
${_arch}-strip --strip-unneeded "${pkgdir}/usr/${_arch}/bin/"*.exe
${_arch}-strip --strip-unneeded "${pkgdir}/usr/${_arch}/bin/"*.dll
${_arch}-strip -g "${pkgdir}/usr/${_arch}/lib/"*.a
done
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |