quickemu-tui-git
maintainer spiriwind
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
Clones and installs a Python script from a Gitee repository (the project's own declared URL), which is a non-whitelisted but plausibly project-owned forge; the only concern is the SKIP'd checksum and low vote count, not any malicious behaviour.
Triggered rules
LOW
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Clones and installs a Python script from a Gitee repository (the project's own declared URL), which is a non-whitelisted but plausibly project-owned forge; the only concern is the SKIP'd checksum and low vote count, not any malicious behaviour.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source=("git+https://gitee.com/tqblyc/quickemu-tui.git")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: spiriwind <ruiting_mail@qq.com>
2
pkgname=quickemu-tui-git
3
pkgrel=1
4
pkgdesc="TUI/CLI manager for quickemu virtual machines (git version)"
5
arch=('x86_64')
6
url="https://gitee.com/tqblyc/quickemu-tui"
7
license=('MIT')
8
depends=('python' 'quickemu')
9
makedepends=('git')
10
options=('!strip')
11
source=("git+https://gitee.com/tqblyc/quickemu-tui.git")
12
sha256sums=('SKIP')
13
14
pkgver() {
15
cd "$pkgname"
16
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
17
}
18
19
package() {
20
cd "$pkgname"
21
install -Dm755 quickemu-tui.py "$pkgdir/usr/bin/quickemu-tui"
22
}
23
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 3 |
| 2026-08-02 00:16:08 | LOW | 3 |
| 2026-08-01 00:11:18 | LOW | 3 |
| 2026-07-31 00:14:10 | LOW | 3 |
| 2026-07-30 00:17:23 | LOW | 3 |
| 2026-07-29 00:25:53 | LOW | 3 |
| 2026-07-28 01:39:33 | LOW | 3 |
| 2026-07-28 01:36:52 | MEDIUM | 2 |