otf-now

maintainer orphaned · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads a font archive from a non-whitelisted but project-plausible host (fontlibrary.org) and processes it with a local script; the installed files are font data, not executable code, limiting worst-case impact to data tampering.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a font archive from a non-whitelisted but project-plausible host (fontlibrary.org) and processes it with a local script; the installed files are font data, not executable code, limiting worst-case impact to data tampering.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source=(https://fontlibrary.org/assets/downloads/now/92f81dc6f3ba4a48ba3e70f5e826207d/now.zip

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Daniel Landau <daniel@landau.fi>
2# Contributor: Lucas Werkmeister <mail@lucaswerkmeister.de>
3# Contributor: jdarch <jda -dot- cloud -plus- archlinux -at- gmail -dot- com>
4
5pkgname=otf-now
6pkgdesc="Now typeface by Alfredo Marco Pradil (OpenType)"
7url='https://fontlibrary.org/en/font/now'
8license=('custom:SIL Open Font License')
9pkgver=1
10pkgrel=2
11depends=('fontconfig' 'xorg-font-utils' 'fontforge')
12arch=('any')
13install=$pkgname.install
14
15source=(https://fontlibrary.org/assets/downloads/now/92f81dc6f3ba4a48ba3e70f5e826207d/now.zip
16 convert.ff
17)
18sha512sums=('963899ef209fb9ccdc0548ee24710b43a6183f9b58224f6c3550ec00cb92a2c7d0930efa92aa90a0d3002814296ff86bfb02b9c630a62ceed72f1e233a105258'
19 '3224a9e0ad2e7082ef04722711a9b4cb79baec4f1af505926ef8f0494047ce9636c9a1315d69e0c3b4bc0a66ac590f95764912bde913ad6183198d11aa3b7bcc')
20
21package() {
22 install -d "${pkgdir}/usr/share/fonts/OTF"
23 install -m644 "${srcdir}/"*.otf "${pkgdir}/usr/share/fonts/OTF/"
24
25 cd "${srcdir}"
26 for f in *.otf
27 do
28 fontforge -script convert.ff $f
29 done
30 install -d "${pkgdir}/usr/share/fonts/TTF"
31 install -m644 "${srcdir}/"*.ttf "${pkgdir}/usr/share/fonts/TTF/"
32
33 install -D -m644 "${srcdir}/OFL-FAQ.txt" "${pkgdir}/usr/share/licenses/${pkgname}/OFL-FAQ.txt"
34}
35

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion