python-llama-index-llms-openai

maintainer enihcam · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The pip install in check() runs inside a temporary venv only to verify the built wheel imports correctly; the source is fetched from the official PyPI CDN with a pinned sha256 checksum, so there is no meaningful supply-chain risk beyond the minor quality concern of using pip in a venv during check rather than relying on system packages.

Triggered rules

LOW pip install of an external package pip_install_external

`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums. Severity reduced: python-* packages routinely use pip.

  • PKGBUILD:24 test-env/bin/pip install installer dist/*.whl --quiet
LOW AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is LOW (confidence 70%): The pip install in check() runs inside a temporary venv only to verify the built wheel imports correctly; the source is fetched from the official PyPI CDN with a pinned sha256 checksum, so there is no meaningful supply-chain risk beyond the minor quality concern of using pip in a venv during check rather than relying on system packages.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Youcef NAFA <youcef.nafa at gmail>
2
3_name=llama-index-llms-openai
4pkgname=python-${_name}
5pkgver=0.7.9
6pkgrel=1
7pkgdesc="llama-index llms openai integration"
8arch=('any')
9url="https://github.com/run-llama/llama_index"
10license=('MIT')
11depends=('python' 'python-openai' 'python-llama-index-core')
12makedepends=('python-hatchling' 'python-build' 'python-installer' 'python-wheel')
13source=("https://files.pythonhosted.org/packages/source/${_name::1}/${_name}/${_name//-/_}-$pkgver.tar.gz")
14sha256sums=('f54a24b717134c86e724007057a06a84394f019d1f01e918b624894e208a86df')
15
16build() {
17 cd "${srcdir}"/${_name//-/_}-${pkgver}
18 python -m build --wheel --no-isolation
19}
20
21check() {
22 cd "${srcdir}"/${_name//-/_}-${pkgver}
23 python -m venv test-env
24 test-env/bin/pip install installer dist/*.whl --quiet
25 test-env/bin/python -c "from llama_index.llms.openai import OpenAI; print('import OK')"
26}
27
28package() {
29 cd "${srcdir}"/${_name//-/_}-${pkgver}
30 python -m installer --destdir="$pkgdir" dist/*.whl
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 3
2026-07-17 00:06:16 LOW 3
2026-07-16 00:05:41 LOW 3
2026-07-15 00:09:25 LOW 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion