onhold-git

LOW
maintainer miller.jona 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The pip install is for the project's own requirements.txt during prepare(), which is normal for Python packages and not inherently dangerous.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install is for the project's own requirements.txt during prepare(), which is normal for Python packages and not inherently dangerous.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium pip install of an external package pip_install_external

`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:23 python3 -m pip install -r requirements.txt

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Jona Miller <miller.jona at yandex dot com>
2pkgname=onhold-git
3pkgver=0.6.4.r6.ga15d8ca
4pkgrel=1
5pkgdesc="A command-line utility that allows you to play music while a long job completes"
6arch=('any')
7url="https://github.com/alexdelorenzo/onhold"
8license=('AGPL3')
9depends=('python>=3.6.0')
10makedepends=('python-pip')
11provides=("${pkgname%-git}")
12conflicts=("${pkgname%-git}")
13source=(${pkgname}::git+${url}.git)
14md5sums=('SKIP')
15
16pkgver() {
17 cd "${srcdir}/${pkgname}"
18 git describe --long --tags | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
19}
20
21prepare() {
22 cd "${srcdir}/${pkgname}"
23 python3 -m pip install -r requirements.txt
24}
25
26build() {
27 cd "${srcdir}/${pkgname}"
28 python3 setup.py build
29}
30
31package() {
32 cd "${srcdir}/${pkgname}"
33 install -Dm644 ./README.md -t "${pkgdir}/usr/share/doc/${pkgname}/"
34 install -Dm644 ./LICENSE -t "${pkgdir}/usr/share/licenses/${pkgname}/"
35 python3 setup.py install --root="${pkgdir}" --optimize=1 --skip-build
36}
37

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion