python-fpyutils
maintainer Frnmst
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a tarball from the project maintainer's personal domain, which is not on a standard code host but plausibly the official source; building from this is normal for AUR packages, and the checksum is provided (though SKIP'd), with no evidence of malicious content or remote code execution.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project maintainer's personal domain, which is not on a standard code host but plausibly the official source; building from this is normal for AUR packages, and the checksum is provided (though SKIP'd), with no evidence of malicious content or remote code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
source=("https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz.sig" "https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Franco Masotti (See /README.md in project source)
2
# Contributor: Franco Masotti (See /README.md in project source)
3
pkgname=python-fpyutils
4
pkgver=4.0.1
5
pkgrel=1
6
pkgdesc="A collection of useful non-standard Python functions which aim to be simple to use"
7
arch=('any')
8
url="https://blog.franco.net.eu.org/software/#fpyutils"
9
license=('GPL3')
10
depends=('python')
11
makedepends=('python-build'
12
'python-installer'
13
'python-wheel'
14
'python-setuptools')
15
options=(!emptydirs)
16
source=("https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz.sig" "https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz")
17
sha512sums=('SKIP' 'dc7f0fa225502cf7cc2f6878fd3d160e15d6f9290e67bb1e24ce51d7a7e2c25d6c3ecc87b0a47ca3aa129639fcc1cfb945d8c1e76bec625b9047a9520d280236')
18
19
check() {
20
cd "${srcdir}"/fpyutils-"${pkgver}"
21
python -m unittest discover --failfast --locals --verbose
22
}
23
24
build() {
25
cd "${srcdir}"/fpyutils-"${pkgver}"
26
python -m build --wheel --no-isolation
27
}
28
29
package() {
30
cd "${srcdir}"/fpyutils-"${pkgver}"
31
python -m installer --destdir="${pkgdir}" dist/*.whl
32
}
33
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |