oneko

maintainer actionless · 37 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from the project's own official website, used to build the software from source; the non-whitelisted host is the project's legitimate domain, and no untrusted executable code is downloaded or executed.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's own official website, used to build the software from source; the non-whitelisted host is the project's legitimate domain, and no untrusted executable code is downloaded or executed.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 "http://www.daidouji.com/$pkgname/distfiles/$pkgname-$_pkgver.tar.gz"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Boohbah <boohbah at gmail.com>
2# Contributor: mathieui <mathieui[at]mathieui.net>
3# Contributor: rayanamukami <matthewchoi_123 at hotmail.com>
4
5pkgname=oneko
6pkgrel=6
7pkgver=1.2.5
8_pkgver="1.2.sakura.5"
9pkgdesc="A cat that chases around your cursor"
10arch=('x86_64' 'i686')
11url="http://www.daidouji.com/oneko/"
12license=('Public Domain')
13depends=('libx11' 'libxext')
14makedepends=('imake' 'make' 'desktop-file-utils')
15source=(
16 "http://www.daidouji.com/$pkgname/distfiles/$pkgname-$_pkgver.tar.gz"
17 "gcc2024.patch"
18 "gcc2025.patch"
19)
20md5sums=('456b318fa6e61431bf4f0a42b110014a'
21 'f6ebbd81cab895f8909fbd26832cfba7'
22 '145b0a52bd79f29fa965f57e4092e0b9')
23
24prepare() {
25 cd "$srcdir/$pkgname-$_pkgver/"
26 patch -Np1 -i ../gcc2024.patch
27 patch -Np1 -i ../gcc2025.patch
28}
29
30build() {
31 cd "$srcdir/$pkgname-$_pkgver/"
32 xmkmf -a
33 make
34}
35
36package() {
37 cd "$srcdir/$pkgname-$_pkgver/"
38 _mandir="$pkgdir/usr/share/man"
39
40 mkdir -p "$_mandir/man1/"
41 mkdir -p "$_mandir/jp/man1/"
42 mkdir -p "$pkgdir/usr/bin"
43
44 make DESTDIR=$pkgdir install
45
46 cp oneko.man "$_mandir/man1/oneko.1"
47 cp oneko.man.jp "$_mandir/jp/man1/oneko.1"
48 echo -e '#!/bin/sh'"\nxsetroot -cursor_name top_left_arrow || xsetroot -cursor_name left_ptr " > "$pkgdir/usr/bin/oneko-restore-cursor"
49 chmod +x "$pkgdir/usr/bin/oneko-restore-cursor"
50}
51

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion