piplib
maintainer harenome
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is downloaded from a non-whitelisted but plausibly project-related host (bastoul.net), which is associated with the upstream author; the package builds from source code, which is normal for AUR packages, and poses minimal risk as it does not execute prebuilt binaries or obfuscated payloads.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from a non-whitelisted but plausibly project-related host (bastoul.net), which is associated with the upstream author; the package builds from source code, which is normal for AUR packages, and poses minimal risk as it does not execute prebuilt binaries or obfuscated payloads.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=(http://www.bastoul.net/cloog/pages/download/${pkgname}-${pkgver}.tar.gz)
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Harenome Ranaivoarivony-Razanajato
2
# <ranaivoarivony-razanajato@hareno.me>
3
4
pkgname=piplib
5
pkgver=1.4.0
6
pkgrel=3
7
pkgdesc="Parametric Integer Programming Library"
8
arch=(x86_64)
9
url="http://www.piplib.org/"
10
license=('LGPL')
11
depends=("gmp")
12
provides=("piplib")
13
source=(http://www.bastoul.net/cloog/pages/download/${pkgname}-${pkgver}.tar.gz)
14
md5sums=('f5d1c7d45c5c40c0d64fa7d6bb143740')
15
16
build() {
17
cd "${srcdir}/${pkgname}-${pkgver}"
18
./configure --prefix=/usr --with-gmp=system
19
sed -i 's/ECHO/echo/' libtool
20
make
21
}
22
23
check() {
24
cd "${srcdir}/${pkgname}-${pkgver}"
25
make check
26
}
27
28
package() {
29
cd "${srcdir}/${pkgname}-${pkgver}"
30
make DESTDIR="${pkgdir}/" install
31
for lib in ${pkgdir}/usr/lib/libpiplib*.so*; do
32
lib=$(basename "${lib}")
33
new_name=$(echo "${lib}" | sed 's/32/_sp/;s/64/_dp/;s/MP/_gmp/')
34
ln -s "${lib}" "${pkgdir}/usr/lib/${new_name}"
35
done
36
}
37
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |