neru-screen-control
The pip install is run during prepare() but only installs dependencies from a requirements.txt file sourced from the project's own GitHub repository, which is a normal and safe practice for bundling dependencies in AUR packages.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install is run during prepare() but only installs dependencies from a requirements.txt file sourced from the project's own GitHub repository, which is a normal and safe practice for bundling dependencies in AUR packages.
1 higher static finding superseded - not the current verdict (shown for transparency)
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:28
.venv/bin/pip install -r requirements.txt --quiet --no-cache-dir
PKGBUILD
1 offending line(s) highlighted# Maintainer: Huzzama <your@email.com>
pkgname=neru-screen-control
pkgver=1.0.0
pkgrel=1
pkgdesc="LCD display controller for Thermalright USB cooler screens"
arch=('any')
url="https://github.com/Huzzama/Neru-screen-control"
license=('MIT')
depends=(
'python>=3.10'
'python-pip'
'libusb'
'polkit'
)
optdepends=(
'python-pyside6: graphical user interface'
'python-pillow: image and frame rendering'
'python-opencv: video playback support'
'python-pynvml: NVIDIA GPU metrics'
)
ssource=("https://github.com/Huzzama/Neru-screen-control/archive/refs/tags/v${pkgver}.tar.gz")
sha256sums=('ac61cc2a7c82e47f2e3a075b4c781751e83a71a9c4d85149ebe723de47c8e5b8')
prepare() {
cd "$srcdir/Neru-screen-control-$pkgver"
# Install Python dependencies into a local venv for packaging
python3 -m venv .venv
.venv/bin/pip install -r requirements.txt --quiet --no-cache-dir
}
package() {
cd "$srcdir/Neru-screen-control-$pkgver"
# Application source files
install -dm755 "$pkgdir/usr/share/$pkgname"
cp -r src main.py icon.png requirements.txt \
"$pkgdir/usr/share/$pkgname/"
# Copy venv (bundled dependencies)
cp -r .venv "$pkgdir/usr/share/$pkgname/venv"
# /usr/bin wrapper
install -dm755 "$pkgdir/usr/bin"
cat > "$pkgdir/usr/bin/$pkgname" << 'WRAPPER'
#!/bin/bash
exec /usr/share/neru-screen-control/venv/bin/python \
/usr/share/neru-screen-control/main.py "$@"
WRAPPER
chmod +x "$pkgdir/usr/bin/$pkgname"
# Desktop launcher
install -Dm644 "packaging/shared/$pkgname.desktop" \
"$pkgdir/usr/share/applications/$pkgname.desktop"
# Icons (all sizes)
for size in 16 32 48 64 128 256; do
install -Dm644 \
"packaging/shared/icons/${size}x${size}/$pkgname.png" \
"$pkgdir/usr/share/icons/hicolor/${size}x${size}/apps/$pkgname.png"
done
# udev rule
install -Dm644 "99-chizhou-display.rules" \
"$pkgdir/usr/lib/udev/rules.d/99-chizhou-display.rules"
# systemd service template (not enabled — user opts in via Settings)
install -Dm644 "packaging/shared/$pkgname.service" \
"$pkgdir/usr/share/$pkgname/$pkgname.service"
# License
install -Dm644 LICENSE \
"$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |