python-moderngl-git
maintainer groctel
· 2 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The pip install in check() installs only the built wheel and test dependencies like numpy and pytest, which are standard and expected for testing; no untrusted external packages are installed.
Triggered rules
LOW
pip install of an external package
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums. Severity reduced: python-* packages routinely use pip.
-
PKGBUILD:53
pip install ./dist/*.whl numpy pytest scipy setuptools
LOW
AI review
llm_review
An AI model (qwen/qwen3-235b-a22b-07-25) reviewed this and agrees it is LOW (confidence 95%): The pip install in check() installs only the built wheel and test dependencies like numpy and pytest, which are standard and expected for testing; no untrusted external packages are installed.
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Groctel <aur@taxorubio.com>
2
# shellcheck disable=SC1091,SC2034,SC2154,SC2164
3
4
_name=moderngl
5
6
pkgname=python-moderngl-git
7
pkgver=5.11.1.r0.g11d3e2ea
8
pkgrel=1
9
pkgdesc="Modern OpenGL binding for python."
10
11
arch=("any")
12
license=("MIT")
13
url="https://github.com/moderngl/moderngl"
14
15
source=("git+$url.git")
16
sha512sums=('SKIP')
17
18
options=(!emptydirs)
19
conflicts=(python-moderngl)
20
21
depends=(
22
"libgl"
23
"python"
24
)
25
makedepends=(
26
"git"
27
"python-build"
28
"python-installer"
29
"python-setuptools"
30
"python-wheel"
31
)
32
checkdepends=(
33
"python-virtualenv"
34
)
35
36
pkgver () {
37
cd "$srcdir/$_name"
38
git describe --long --tags | sed 's/^networkx-//;s/\([^-]*-g\)/r\1/;s/-/./g'
39
}
40
41
build () {
42
cd "$srcdir/$_name"
43
python -m build --wheel --no-isolation
44
}
45
46
check () {
47
cd "$srcdir/$_name"
48
49
50
python -m venv venv
51
(
52
source venv/bin/activate
53
pip install ./dist/*.whl numpy pytest scipy setuptools
54
python setup.py build_ext -i
55
python -m pytest
56
)
57
rm -rf venv
58
}
59
60
package () {
61
cd "$srcdir/$_name"
62
python -m installer --destdir="$pkgdir" dist/*.whl
63
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
64
}
65
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |