mingw-w64-libgpg-error

LOW
maintainer patlefort 8 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The source is downloaded from the official project domain (gnupg.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own official site, not a third-party or personal host, so the download is trustworthy despite the static analyzer flag.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the official project domain (gnupg.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own official site, not a third-party or personal host, so the download is trustworthy despite the static analyzer flag.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source=("https://www.gnupg.org/ftp/gcrypt/libgpg-error/libgpg-error-${pkgver}.tar.bz2"{,.sig}

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Patrick Northon <northon_patrick3@yahoo.ca>
2# Contributor: Andrew Sun <adsun701 at gmail dot com>
3
4pkgname=mingw-w64-libgpg-error
5pkgver=1.61
6pkgrel=1
7pkgdesc="Support library for libgcrypt (mingw-w64)"
8arch=(any)
9url="http://www.gnupg.org"
10license=(LGPL-2.1-or-later
11 'BSD-3-Clause OR LGPL-2.1-or-later'
12 FSFULLR
13 GPL-2.0-or-later)
14makedepends=('mingw-w64-configure')
15depends=('mingw-w64-crt')
16options=(staticlibs !strip !buildflags)
17source=("https://www.gnupg.org/ftp/gcrypt/libgpg-error/libgpg-error-${pkgver}.tar.bz2"{,.sig}
18 "02-fix-symbollist-on.mingw.patch"
19 "05-w32-gen.all.patch"
20 "07-windows-build.patch")
21sha256sums=('7a85413f2bc354f4f8aa832b718af122e48965e9e0eb9012ee659c13c6385c93'
22 'SKIP'
23 '364da17febff3f6eeffee5a5f1e3ed1b644adeb5ca48a972c5c4675c10238a91'
24 '9ccdc567810d58526888fd11c5f7d01101627011840b7b75a91e96aa9e71f49d'
25 'f62a8464414a65b1aac20820d4f4eeb0aa25e5c865aa4ba5914f1f10a41d336d')
26validpgpkeys=('6DAA6E64A76D2840571B4902528897B826403ADA' # Werner Koch (dist signing 2020)
27 'AC8E115BF73E2D8D47FA9908E98E9B2D19C6C8BD') # Niibe Yutaka (GnuPG Release Key)
28_architectures="${MINGW_W64_ARCHS:-x86_64-w64-mingw32}"
29
30prepare() {
31 cd "${srcdir}/libgpg-error-${pkgver}"
32 patch -p1 -i "${srcdir}/02-fix-symbollist-on.mingw.patch"
33 patch -p1 -i "${srcdir}/05-w32-gen.all.patch"
34 patch -p1 -i "${srcdir}/07-windows-build.patch"
35 autoreconf -fiv
36}
37
38build() {
39 cd "${srcdir}/libgpg-error-${pkgver}"
40 for _arch in ${_architectures}; do
41 unset LDFLAGS
42 mkdir -p build-${_arch} && pushd build-${_arch}
43 ${_arch}-configure
44 make
45 popd
46 done
47}
48
49package() {
50 for _arch in ${_architectures}; do
51 cd "${srcdir}/libgpg-error-${pkgver}/build-${_arch}"
52 make DESTDIR="${pkgdir}" install
53 find "${pkgdir}/usr/${_arch}" -name '*.exe' -exec ${_arch}-strip {} \;
54 find "${pkgdir}/usr/${_arch}" -name '*.dll' -exec ${_arch}-strip --strip-unneeded {} \;
55 find "${pkgdir}/usr/${_arch}" -name '*.a' -o -name '*.dll' | xargs ${_arch}-strip -g
56 rm -rf "${pkgdir}/usr/${_arch}/share/info/dir"
57 done
58}
59

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion