neferwl-git

LOW
maintainer bnema 0 votes scanned 2026-10-07 18:06:17.708834
View on AUR
Why flagged

Package builds from a legitimate project's own Git repository, uses SKIP only because the source is a git checkout, and performs standard Go build steps without executing untrusted remote code; the flagged low votes and recent upload are minor trust indicators but do not imply malice.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): Package builds from a legitimate project's own Git repository, uses SKIP only because the source is a git checkout, and performs standard Go build steps without executing untrusted remote code; the flagged low votes and recent upload are minor trust indicators but do not imply malice.

PKGBUILD

1# Maintainer: bnema <b at bnema dot dev>
2# The release workflow sets pkgver and publishes this file to the AUR on every
3# release tag, so the AUR version never falls behind the latest tag.
4pkgname=neferwl-git
5pkgver=0.6.0.r0.g2732965
6pkgrel=1
7pkgdesc='A Wayland compositor that spends its frames on your apps, not on itself (git version)'
8arch=('x86_64' 'aarch64')
9url='https://github.com/bnema/neferwl'
10license=('GPL-3.0-only')
11# Loaded at runtime (purego, no cgo): not seen by makepkg's library scan.
12depends=('glibc' 'libinput' 'libxkbcommon' 'seatd' 'systemd-libs' 'vulkan-icd-loader'
13 'vulkan-driver' 'wayland' 'dbus' 'libcap')
14makedepends=('go>=2:1.27' 'git')
15optdepends=('xwayland-satellite>=0.7: X11 apps'
16 'foot: default terminal'
17 'fuzzel: launcher'
18 'xdg-desktop-portal-gtk: file pickers and settings for apps'
19 'xdg-desktop-portal-wlr: screen sharing and screenshots through the portal'
20 'nefercap: screenshots and screen recording')
21provides=('neferwl')
22conflicts=('neferwl' 'neferwl-bin')
23install=neferwl.install
24source=('git+https://github.com/bnema/neferwl.git')
25sha256sums=('SKIP')
26
27pkgver() {
28 cd neferwl
29 # v0.2.0-5-gabc1234 -> 0.2.0.r5.gabc1234. Pre-release tags (v0.3.0-rc1)
30 # are skipped: pacman sorts 0.3.0.rc1 after 0.3.0.
31 git describe --long --tags --abbrev=7 --exclude='*-*' | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
32}
33
34prepare() {
35 cd neferwl
36 export GOPATH="$srcdir/gopath" GOFLAGS='-mod=readonly -modcacherw' GOTOOLCHAIN=local
37 go mod download
38}
39
40build() {
41 cd neferwl
42 export GOPATH="$srcdir/gopath" CGO_ENABLED=0 GOTOOLCHAIN=local GOPROXY=off
43 export GOFLAGS='-mod=readonly -modcacherw -trimpath -buildvcs=false -buildmode=pie'
44 go build -ldflags "-X main.version=$pkgver" -o neferwl ./cmd/neferwl
45}
46
47check() {
48 cd neferwl
49 ./neferwl version
50 ./neferwl validate-config examples/config
51}
52
53package() {
54 cd neferwl
55 install -Dm755 neferwl "$pkgdir/usr/bin/neferwl"
56 install -Dm755 packaging/neferwl-session "$pkgdir/usr/bin/neferwl-session"
57 install -Dm644 packaging/neferwl.service "$pkgdir/usr/lib/systemd/user/neferwl.service"
58 install -Dm644 packaging/neferwl-shutdown.target "$pkgdir/usr/lib/systemd/user/neferwl-shutdown.target"
59 install -Dm644 packaging/neferwl.desktop "$pkgdir/usr/share/wayland-sessions/neferwl.desktop"
60 install -Dm644 packaging/neferwl-portals.conf "$pkgdir/usr/share/xdg-desktop-portal/neferwl-portals.conf"
61 install -Dm644 examples/config "$pkgdir/usr/share/doc/neferwl/config.example"
62 install -Dm644 examples/capture-allow "$pkgdir/usr/share/doc/neferwl/capture-allow.example"
63 install -Dm644 README.md "$pkgdir/usr/share/doc/neferwl/README.md"
64 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
65}
66

Changes since previous scan

--- PKGBUILD @ 2026-10-06 00:13
+++ PKGBUILD @ 2026-10-07 18:06
@@ -2,7 +2,7 @@
# The release workflow sets pkgver and publishes this file to the AUR on every
# release tag, so the AUR version never falls behind the latest tag.
pkgname=neferwl-git
-pkgver=0.5.0.r0.gccce658
+pkgver=0.6.0.r0.g2732965
pkgrel=1
pkgdesc='A Wayland compositor that spends its frames on your apps, not on itself (git version)'
arch=('x86_64' 'aarch64')

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 18:06:17 Low 2
2026-10-06 00:13:36 Clean 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion