moarchy-atlas

CLEAN
maintainer simonschubert 0 votes scanned 2026-09-29 00:07:46.805866
View on AUR

Triggered rules

Clean AI review downgraded a static finding llm_review

The static rules flagged this LOW, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it CLEAN (confidence 95%): The package builds from a tagged release asset on the project's own GitHub repository, installs only QML/JS files and a launcher script, and has a clear, auditable source with no remote code execution or untrusted dependencies.

1 higher static finding superseded - not the current verdict (shown for transparency)
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

PKGBUILD

1# Maintainer: Simon Schubert <simon@librem.one>
2#
3# Atlas as an app: the QML tree in /usr/share/moarchy-atlas, started by
4# /usr/bin/moarchy-atlas. That launcher opens it in the running Omarchy shell
5# when the plugin is installed there, and as its own Quickshell process
6# everywhere else -- so this package needs Quickshell, not Omarchy.
7pkgname=moarchy-atlas
8pkgver=0.1.0
9pkgrel=1
10pkgdesc='Flags, capitals and facts for every country, and a flag quiz, for Quickshell'
11arch=('any')
12url='https://github.com/SimonSchubert/moarchy-apps'
13license=('MIT')
14# qt6-declarative (QtQuick) comes with quickshell. curl makes the three
15# requests to REST Countries and fetches the flags. The kit's icons are Nerd
16# Font glyphs, which namcap cannot see, so it calls that dependency unneeded.
17depends=('quickshell' 'curl' 'ttf-jetbrains-mono-nerd' 'hicolor-icon-theme')
18# A release asset that packaging/release.sh builds from apps/atlas at the tag,
19# with shared/kit in place of the kit link -- not GitHub's generated archive,
20# whose compression has moved under pinned checksums before.
21source=("$url/releases/download/atlas-v$pkgver/$pkgname-$pkgver.tar.gz")
22# Pinned in the commit after the tag, as every app's here is.
23sha256sums=('53a3f332a80fb0c74294038aeb140521086b71da78dd5bcb4160e2d948d4c89e')
24
25check() {
26 cd "$pkgname-$pkgver"
27 # REST Countries' JSON, our three files, the quiz's rules and every figure
28 # on screen, against a fixture. No display and no network needed.
29 QT_QPA_PLATFORM=offscreen /usr/lib/qt6/bin/qmltestrunner -input tests
30}
31
32package() {
33 cd "$pkgname-$pkgver"
34
35 install -d "$pkgdir/usr/share/$pkgname/kit"
36 install -m644 manifest.json ./*.qml ./*.js icon.svg "$pkgdir/usr/share/$pkgname/"
37 install -m644 kit/*.qml kit/*.js "$pkgdir/usr/share/$pkgname/kit/"
38
39 install -Dm755 bin/moarchy-atlas "$pkgdir/usr/bin/moarchy-atlas"
40 install -Dm644 org.moarchy.Atlas.desktop \
41 "$pkgdir/usr/share/applications/org.moarchy.Atlas.desktop"
42 install -Dm644 icon.svg "$pkgdir/usr/share/icons/hicolor/scalable/apps/org.moarchy.Atlas.svg"
43 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
44}
45

Scan history

Scanned at (UTC)SeverityRules
2026-09-29 00:07:46 Clean 2
2026-09-28 23:22:18 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion