mingw-w64-libgpg-error
The source is downloaded from the official project domain (gnupg.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own official site, not a third-party or personal host, so the download is trustworthy despite the static analyzer flag.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the official project domain (gnupg.org), which is legitimate and expected for this package; the non-whitelisted host is the project's own official site, not a third-party or personal host, so the download is trustworthy despite the static analyzer flag.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=("https://www.gnupg.org/ftp/gcrypt/libgpg-error/libgpg-error-${pkgver}.tar.bz2"{,.sig}
PKGBUILD
1 offending line(s) highlighted# Maintainer: Patrick Northon <northon_patrick3@yahoo.ca>
# Contributor: Andrew Sun <adsun701 at gmail dot com>
pkgname=mingw-w64-libgpg-error
pkgver=1.61
pkgrel=1
pkgdesc="Support library for libgcrypt (mingw-w64)"
arch=(any)
url="http://www.gnupg.org"
license=(LGPL-2.1-or-later
'BSD-3-Clause OR LGPL-2.1-or-later'
FSFULLR
GPL-2.0-or-later)
makedepends=('mingw-w64-configure')
depends=('mingw-w64-crt')
options=(staticlibs !strip !buildflags)
source=("https://www.gnupg.org/ftp/gcrypt/libgpg-error/libgpg-error-${pkgver}.tar.bz2"{,.sig}
"02-fix-symbollist-on.mingw.patch"
"05-w32-gen.all.patch"
"07-windows-build.patch")
sha256sums=('7a85413f2bc354f4f8aa832b718af122e48965e9e0eb9012ee659c13c6385c93'
'SKIP'
'364da17febff3f6eeffee5a5f1e3ed1b644adeb5ca48a972c5c4675c10238a91'
'9ccdc567810d58526888fd11c5f7d01101627011840b7b75a91e96aa9e71f49d'
'f62a8464414a65b1aac20820d4f4eeb0aa25e5c865aa4ba5914f1f10a41d336d')
validpgpkeys=('6DAA6E64A76D2840571B4902528897B826403ADA' # Werner Koch (dist signing 2020)
'AC8E115BF73E2D8D47FA9908E98E9B2D19C6C8BD') # Niibe Yutaka (GnuPG Release Key)
_architectures="${MINGW_W64_ARCHS:-x86_64-w64-mingw32}"
prepare() {
cd "${srcdir}/libgpg-error-${pkgver}"
patch -p1 -i "${srcdir}/02-fix-symbollist-on.mingw.patch"
patch -p1 -i "${srcdir}/05-w32-gen.all.patch"
patch -p1 -i "${srcdir}/07-windows-build.patch"
autoreconf -fiv
}
build() {
cd "${srcdir}/libgpg-error-${pkgver}"
for _arch in ${_architectures}; do
unset LDFLAGS
mkdir -p build-${_arch} && pushd build-${_arch}
${_arch}-configure
make
popd
done
}
package() {
for _arch in ${_architectures}; do
cd "${srcdir}/libgpg-error-${pkgver}/build-${_arch}"
make DESTDIR="${pkgdir}" install
find "${pkgdir}/usr/${_arch}" -name '*.exe' -exec ${_arch}-strip {} \;
find "${pkgdir}/usr/${_arch}" -name '*.dll' -exec ${_arch}-strip --strip-unneeded {} \;
find "${pkgdir}/usr/${_arch}" -name '*.a' -o -name '*.dll' | xargs ${_arch}-strip -g
rm -rf "${pkgdir}/usr/${_arch}/share/info/dir"
done
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |