openmesh
The source is a legitimate project release tarball from a university-hosted domain (rwth-aachen.de), which is plausibly the official project infrastructure; building from this source is normal AUR packaging behavior and poses no significant supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a legitimate project release tarball from a university-hosted domain (rwth-aachen.de), which is plausibly the official project infrastructure; building from this source is normal AUR packaging behavior and poses no significant supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:20
source=("${pkgname}-${pkgver}.tar.bz2::https://www.graphics.rwth-aachen.de/media/${pkgname}_static/Releases/${pkgver%.*}/${_pkgname}-${pkgver}.tar.bz2"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Chirantan Ekbote <chirantan.ekbote at gmail.com>
# Contributor: Brian Schubert <bewschubert@gmail.com>
_build_doc=OFF
_build_apps=ON
_pkgname=OpenMesh
pkgname=openmesh
pkgver=11.0.0
pkgrel=1
pkgdesc="A generic and efficient data structure for representing and manipulating polygonal meshes"
arch=('i686' 'x86_64')
url="http://www.openmesh.org"
license=('BSD-3-Clause')
depends=(
'gcc-libs'
'glibc'
'libglvnd'
'qt5-base'
)
source=("${pkgname}-${pkgver}.tar.bz2::https://www.graphics.rwth-aachen.de/media/${pkgname}_static/Releases/${pkgver%.*}/${_pkgname}-${pkgver}.tar.bz2"
doc-install.patch)
b2sums=(
'5f4eb34365cfeedab8e5de818db955ed1a5ab42d2289e9ab686efda0f3057462848bdee0b53af0f81ddc6ea388ef64eecde923f468beb2078a77f2dff5c04753'
'02336dbec8dddce14fdd6aba042ff356ca3cc5d783269bb8cf9b1f2ab75c8a525fd43fb44e61341db210cdbcb048f6771a3c8c8fd86ed6e46de74c8e0dc60d4a'
)
if [[ "${_build_doc}" == "ON" && "${_build_apps}" == "ON" ]]; then
makedepends=('cmake' 'qt5-base' 'graphviz' 'doxygen')
elif [[ "${_build_doc}" == "ON" ]]; then
makedepends=('cmake' 'graphviz' 'doxygen')
elif [[ "${_build_apps}" == "ON" ]]; then
makedepends=('cmake' 'qt5-base')
else
makedepends=('cmake')
fi
prepare() {
cd "${srcdir}/OpenMesh-${pkgver}" || exit 1
if [[ "${_build_doc}" == "ON" ]]; then
patch -Np1 -i "${srcdir}"/doc-install.patch
fi
}
build() {
cd "${srcdir}/OpenMesh-${pkgver}" || exit 1
mkdir -p build && cd build || exit 1
cmake \
-DCMAKE_BUILD_TYPE=Release \
-DCMAKE_INSTALL_PREFIX=/usr \
-DBUILD_APPS=${_build_apps} \
..
make
if [[ "${_build_doc}" == "ON" ]]; then
make doc
fi
}
package() {
cd "${srcdir}"/OpenMesh-${pkgver}/build || exit 1
make DESTDIR="${pkgdir}" install
# install licenses
mkdir -p "${pkgdir}"/usr/share/licenses/openmesh/
install -D -m644 ../LICENSE \
"${pkgdir}"/usr/share/licenses/openmesh/
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |