python-protobuf-py

LOW
maintainer medaminezghal 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package builds from the project's own source via git and includes a proto file from GitHub, both from plausible project-owned locations; the prebuilt wheel from pythonhosted.org is checksummed and used as a build tool, not executed directly, posing minimal risk; the flagged low votes and recent upload are minor trust concerns but do not indicate active malice.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 90%): The package builds from the project's own source via git and includes a proto file from GitHub, both from plausible project-owned locations; the prebuilt wheel from pythonhosted.org is checksummed and used as a build tool, not executed directly, posing minimal risk; the flagged low votes and recent upload are minor trust concerns but do not indicate active malice.

PKGBUILD

1# Maintainer: Mohamed Amine Zghal (medaminezghal) <medaminezghal at outlook dot com>
2
3_name=protobuf-py
4pkgname=python-$_name
5pkgver=0.6.0
6_protobuf_ver=36.1
7pkgrel=1
8pkgdesc='Idiomatic Protocol Buffers for Python.'
9arch=('x86_64' 'aarch64')
10url='https://github.com/bufbuild/protobuf-py'
11license=('Apache-2.0')
12depends=('python'
13 'python-typing_extensions')
14makedepends=('python-uv-build'
15 'python-build'
16 'python-installer'
17 'python-wheel'
18 'git')
19checkdepends=('python-hypothesis'
20 'python-pytest'
21 'python-pydantic')
22optdepends=('python-pydantic')
23source=("$_name::git+$url.git#tag=v$pkgver"
24 "https://github.com/googleapis/googleapis/raw/refs/heads/master/google/rpc/status.proto")
25source_x86_64=("https://files.pythonhosted.org/packages/py3/p/protoc-runner/protoc_runner-$_protobuf_ver-py3-none-manylinux2014_$CARCH.manylinux_2_17_$CARCH.musllinux_1_1_$CARCH.whl")
26source_aarch64=("https://files.pythonhosted.org/packages/py3/p/protoc-runner/protoc_runner-$_protobuf_ver-py3-none-manylinux2014_$CARCH.manylinux_2_17_$CARCH.musllinux_1_1_$CARCH.whl")
27noextract=("protoc_runner-$_protobuf_ver-py3-none-manylinux2014_$CARCH.manylinux_2_17_$CARCH.musllinux_1_1_$CARCH.whl")
28sha256sums=('024e0c9784c5c697e88d244a1de4a92abe77d54673d75efc7c91f0f5d7ecdf9b'
29 'SKIP')
30sha256sums_x86_64=('7dc4894afdc87f213fcc51a974520ac68d6641406811d671ef23caa2ecd88220')
31sha256sums_aarch64=('03b0f9bee44c5ce2ac601a88c8b35ea5b25e30d585ce95e67b32d35f14015edf')
32
33prepare() {
34 cd "$srcdir"/$_name
35 # Use the uv_build version shipped by Arch
36 sed -i 's/uv_build>=0.12.1,<0.13/uv_build/' pyproject.toml
37 sed -i 's/uv_build>=0.12.1,<0.13/uv_build/' packages/protoc-gen-py/pyproject.toml
38 sed -i 's/uv_build>=0.12.1,<0.13/uv_build/' packages/upstream-protobuf/pyproject.toml
39 mkdir -p "$srcdir"/googleapis/google/rpc/
40 cp -f "$srcdir"/status.proto "$srcdir"/googleapis/google/rpc/status.proto
41}
42
43build() {
44 cd "$srcdir"/$_name
45 python -m build --wheel --no-isolation
46 python -m build --wheel --no-isolation packages/protoc-gen-py
47 python -m build --wheel --no-isolation packages/upstream-protobuf
48}
49
50check() {
51 local pytest_options=(
52 -vv
53 --disable-warnings
54 --override-ini="addopts="
55 )
56 cd "$srcdir"/$_name
57 python -m venv --system-site-packages test-env
58 test-env/bin/python -m installer dist/*.whl
59 test-env/bin/python -m installer packages/protoc-gen-py/dist/*.whl
60 test-env/bin/python -m installer packages/upstream-protobuf/dist/*.whl
61 test-env/bin/python -m installer "$srcdir"/*.whl
62 test-env/bin/protoc --plugin=protoc-gen-py=test-env/bin/protoc-gen-py --proto_path="$srcdir"/googleapis --py_out="$(test-env/bin/python -c 'import sysconfig; print(sysconfig.get_path("purelib"))')" --py_opt=init_files=false google/rpc/status.proto
63 test-env/bin/python -P -m pytest "${pytest_options[@]}" tests
64}
65
66package() {
67 cd "$srcdir"/$_name
68 python -m installer --destdir="$pkgdir" dist/*.whl
69}
70

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion