moarchy-atlas
CLEAN
maintainer simonschubert
0 votes
scanned 2026-09-29 00:07:46.805866
Triggered rules
Clean
AI review downgraded a static finding
llm_review
The static rules flagged this LOW, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it CLEAN (confidence 95%): The package builds from a tagged release asset on the project's own GitHub repository, installs only QML/JS files and a launcher script, and has a clear, auditable source with no remote code execution or untrusted dependencies.
1 higher static finding superseded - not the current verdict (shown for transparency)
Low
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
PKGBUILD
1
# Maintainer: Simon Schubert <simon@librem.one>
2
#
3
# Atlas as an app: the QML tree in /usr/share/moarchy-atlas, started by
4
# /usr/bin/moarchy-atlas. That launcher opens it in the running Omarchy shell
5
# when the plugin is installed there, and as its own Quickshell process
6
# everywhere else -- so this package needs Quickshell, not Omarchy.
7
pkgname=moarchy-atlas
8
pkgver=0.1.0
9
pkgrel=1
10
pkgdesc='Flags, capitals and facts for every country, and a flag quiz, for Quickshell'
11
arch=('any')
12
url='https://github.com/SimonSchubert/moarchy-apps'
13
license=('MIT')
14
# qt6-declarative (QtQuick) comes with quickshell. curl makes the three
15
# requests to REST Countries and fetches the flags. The kit's icons are Nerd
16
# Font glyphs, which namcap cannot see, so it calls that dependency unneeded.
17
depends=('quickshell' 'curl' 'ttf-jetbrains-mono-nerd' 'hicolor-icon-theme')
18
# A release asset that packaging/release.sh builds from apps/atlas at the tag,
19
# with shared/kit in place of the kit link -- not GitHub's generated archive,
20
# whose compression has moved under pinned checksums before.
21
source=("$url/releases/download/atlas-v$pkgver/$pkgname-$pkgver.tar.gz")
22
# Pinned in the commit after the tag, as every app's here is.
23
sha256sums=('53a3f332a80fb0c74294038aeb140521086b71da78dd5bcb4160e2d948d4c89e')
24
25
check() {
26
cd "$pkgname-$pkgver"
27
# REST Countries' JSON, our three files, the quiz's rules and every figure
28
# on screen, against a fixture. No display and no network needed.
29
QT_QPA_PLATFORM=offscreen /usr/lib/qt6/bin/qmltestrunner -input tests
30
}
31
32
package() {
33
cd "$pkgname-$pkgver"
34
35
install -d "$pkgdir/usr/share/$pkgname/kit"
36
install -m644 manifest.json ./*.qml ./*.js icon.svg "$pkgdir/usr/share/$pkgname/"
37
install -m644 kit/*.qml kit/*.js "$pkgdir/usr/share/$pkgname/kit/"
38
39
install -Dm755 bin/moarchy-atlas "$pkgdir/usr/bin/moarchy-atlas"
40
install -Dm644 org.moarchy.Atlas.desktop \
41
"$pkgdir/usr/share/applications/org.moarchy.Atlas.desktop"
42
install -Dm644 icon.svg "$pkgdir/usr/share/icons/hicolor/scalable/apps/org.moarchy.Atlas.svg"
43
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
44
}
45
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-29 00:07:46 | Clean | 2 |
| 2026-09-28 23:22:18 | Low | 1 |