pixilang-doc
maintainer StanislavSM
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
Downloads a PDF documentation file from warmplace.ru (the official Pixilang project site), converts it to a man page using standard tools, and installs it as non-executable data; the worst case of a swapped source is a corrupted/malicious doc file, not code execution, and the checksum provides integrity verification.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 80%): Downloads a PDF documentation file from warmplace.ru (the official Pixilang project site), converts it to a man page using standard tools, and installs it as non-executable data; the worst case of a swapped source is a corrupted/malicious doc file, not code execution, and the checksum provides integrity verification.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:8
source=("pixilang.7.pdf::https://warmplace.ru/soft/pixilang/Pixilang%20User%20Manual.pdf")
PKGBUILD
1 offending line(s) highlighted
1
pkgname=pixilang-doc
2
pkgver=3.8.6f
3
pkgrel=1
4
pkgdesc="Oficial Pixilang Programmin Language documentation in man-style"
5
arch=('any')
6
depends=('man-db')
7
makedepends=('curl' 'pandoc' 'poppler')
8
source=("pixilang.7.pdf::https://warmplace.ru/soft/pixilang/Pixilang%20User%20Manual.pdf")
9
sha256sums=('8417cf883c01200adfba818365a78e084c7460e694553c136295d1e90ead7608')
10
license=('unknown')
11
pkgver() {
12
curl -sL https://warmplace.ru/soft/pixilang/ | html2text | grep -m 1 -oE "[0-9][.][0-9][.][0-9][a-z]?"
13
}
14
15
makedepends=('pandoc' 'poppler')
16
17
prepare() {
18
pdftohtml -noframes -s "${srcdir}/pixilang.7.pdf" "${srcdir}/manual_temp"
19
20
}
21
22
build() {
23
pandoc "${srcdir}/manual_temp.html" -s -f html -t man \
24
--wrap=preserve \
25
--strip-comments \
26
-M title="PIXILANG" \
27
-M section="7" \
28
-M date="$(date +%Y-%m-%d)" \
29
-M header="Справочник Pixilang" \
30
-M footer="Pixilang Project" \
31
-o "${srcdir}/pixilang.7"
32
33
rm -f ${srcdir}/manual_temp*
34
35
36
}
37
38
39
# Функция установки готового man в систему
40
package() {
41
install -Dm644 "${srcdir}/pixilang.7" "${pkgdir}/usr/share/man/man7/pixilang.7"
42
}
43
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 3 |
| 2026-08-01 00:11:18 | LOW | 3 |
| 2026-07-31 00:14:10 | LOW | 3 |
| 2026-07-30 00:17:23 | LOW | 3 |
| 2026-07-29 00:25:53 | LOW | 3 |
| 2026-07-28 00:07:28 | LOW | 3 |
| 2026-07-27 00:24:32 | LOW | 3 |
| 2026-07-26 00:07:32 | LOW | 3 |
| 2026-07-25 00:13:44 | LOW | 3 |
| 2026-07-24 00:02:28 | LOW | 3 |
| 2026-07-23 00:14:47 | LOW | 3 |
| 2026-07-22 00:29:32 | LOW | 3 |
| 2026-07-21 00:24:15 | LOW | 3 |
| 2026-07-20 00:19:49 | LOW | 3 |
| 2026-07-19 19:12:02 | MEDIUM | 2 |
| 2026-07-19 15:12:45 | LOW | 3 |
| 2026-07-19 15:11:12 | MEDIUM | 2 |