mingw-w64-mumps

LOW
maintainer xantares 0 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The source is a tarball from the project's official domain (mumps-solver.org), which is plausibly the project's own; building from official source is normal AUR packaging, even if the host is not on a standard whitelist.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's official domain (mumps-solver.org), which is plausibly the project's own; building from official source is normal AUR packaging, even if the host is not on a standard whitelist.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=("https://mumps-solver.org/MUMPS_${pkgver}.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1pkgname=mingw-w64-mumps
2pkgver=5.9.1
3pkgrel=1
4pkgdesc='Sparse solver library using Gaussian elimination (mingw-w64)'
5url='https://mumps-solver.org'
6license=('CECILL-C')
7depends=('mingw-w64-lapack')
8makedepends=('mingw-w64-gcc')
9arch=('any')
10options=('!buildflags' '!strip' 'staticlibs')
11source=("https://mumps-solver.org/MUMPS_${pkgver}.tar.gz")
12sha256sums=('659c9b57646b5a003ac618baa1faf9dd2044e46c732b3daaccbc7158003e1b46')
13
14_architectures=${MINGW_W64_ARCHS:-x86_64-w64-mingw32}
15
16prepare () {
17 cd "${srcdir}/MUMPS_${pkgver}"
18 cp Make.inc/Makefile.inc.generic.SEQ Makefile.inc
19
20 # calling convention
21 sed -i "s|define MUMPS_CALL|define MUMPS_CALL __declspec(dllexport)|g" include/mumps_compat.h
22
23 # static inline + __declspec(dllexport) does not make sense
24 sed -i "s|define MUMPS_INLINE static inline|define MUMPS_INLINE|g" include/mumps_compat.h
25
26 # fortran mangling
27 sed -i "s/#if defined(UPPER) || defined(MUMPS_WIN32)/#if defined(UPPER)/g" src/mumps_common.h
28 sed -i "s/if defined(UPPER) || defined(MUMPS_WIN32)/if defined(UPPER)/g" src/mumps_c.c
29}
30
31build() {
32 cd "${srcdir}"
33 for _arch in ${_architectures}; do
34 cp -r MUMPS_${pkgver} build-${_arch} && pushd build-${_arch}
35 make -C src ../include/mumps_int_def.h
36 make CC=${_arch}-gcc OPTC="-D_FORTIFY_SOURCE=3 -O2 -pipe -fexceptions --param=ssp-buffer-size=4" FC=${_arch}-gfortran FL=${_arch}-gfortran OPTF="-O2 -fallow-argument-mismatch" AR="${_arch}-ar vr " RANLIB=${_arch}-ranlib LIBOTHERS="-lpthread -lssp" -j1
37 popd
38 done
39}
40
41package() {
42 for _arch in ${_architectures}; do
43 cd "${srcdir}"/build-${_arch}
44 install -d "${pkgdir}"/usr/${_arch}/{include/mumps_seq,lib}
45 install -m644 include/*.h "${pkgdir}"/usr/${_arch}/include
46 install -m644 lib/*.a "${pkgdir}"/usr/${_arch}/lib
47 install -m644 libseq/*.h "${pkgdir}"/usr/${_arch}/include/mumps_seq
48 done
49}
50

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion