python-fpyutils

maintainer Frnmst · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from the project maintainer's personal domain, which is not on a standard code host but plausibly the official source; building from this is normal for AUR packages, and the checksum is provided (though SKIP'd), with no evidence of malicious content or remote code execution.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project maintainer's personal domain, which is not on a standard code host but plausibly the official source; building from this is normal for AUR packages, and the checksum is provided (though SKIP'd), with no evidence of malicious content or remote code execution.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source=("https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz.sig" "https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Franco Masotti (See /README.md in project source)
2# Contributor: Franco Masotti (See /README.md in project source)
3pkgname=python-fpyutils
4pkgver=4.0.1
5pkgrel=1
6pkgdesc="A collection of useful non-standard Python functions which aim to be simple to use"
7arch=('any')
8url="https://blog.franco.net.eu.org/software/#fpyutils"
9license=('GPL3')
10depends=('python')
11makedepends=('python-build'
12 'python-installer'
13 'python-wheel'
14 'python-setuptools')
15options=(!emptydirs)
16source=("https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz.sig" "https://blog.franco.net.eu.org/software/fpyutils-${pkgver}/fpyutils-${pkgver}.tar.gz")
17sha512sums=('SKIP' 'dc7f0fa225502cf7cc2f6878fd3d160e15d6f9290e67bb1e24ce51d7a7e2c25d6c3ecc87b0a47ca3aa129639fcc1cfb945d8c1e76bec625b9047a9520d280236')
18
19check() {
20 cd "${srcdir}"/fpyutils-"${pkgver}"
21 python -m unittest discover --failfast --locals --verbose
22}
23
24build() {
25 cd "${srcdir}"/fpyutils-"${pkgver}"
26 python -m build --wheel --no-isolation
27}
28
29package() {
30 cd "${srcdir}"/fpyutils-"${pkgver}"
31 python -m installer --destdir="${pkgdir}" dist/*.whl
32}
33

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion