razercfg

LOW
maintainer jeromedc 2 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is hosted on the maintainer's plausible personal domain (bues.ch) which is not on the standard whitelist, but the package builds from verifiable source code and includes a PGP signature check, making it a low-risk, legitimate AUR package.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is hosted on the maintainer's plausible personal domain (bues.ch) which is not on the standard whitelist, but the package builds from verifiable source code and includes a PGP signature check, making it a low-risk, legitimate AUR package.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:19 source=("https://bues.ch/razercfg/razercfg-$pkgver.tar.xz"{,.asc})

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Jérôme de Courval <decje9@gmail.com>
2# Contributor: Michał Wojdyła < micwoj9292 at gmail dot com >
3# Contributor: Daniel M. Capella <polyzen@archlinux.org>
4# Contributor: Maxwell "Synthead" Pray <synthead@gmail.com>
5# Contributor: Fergus Symon <fergofrog@fergofrog.com>
6
7pkgname=razercfg
8pkgver=0.43
9pkgrel=10
10pkgdesc='Razer mouse configuration tool'
11arch=('x86_64')
12url=https://bues.ch/cms/hacking/razercfg
13license=('GPL-2.0-or-later')
14depends=('bash' 'hicolor-icon-theme' 'libusb' 'python')
15makedepends=('cmake' 'systemd' 'python-setuptools')
16optdepends=('python-pyqt5: for the graphical qrazercfg tool')
17provides=('razerd')
18backup=('etc/razer.conf')
19source=("https://bues.ch/razercfg/razercfg-$pkgver.tar.xz"{,.asc})
20sha512sums=('0d852c86846f14a5da64350e8c0de5288fc9ad6dbbaf4e35b8aea4c9e11eb43269240bc13deac3a49940557846c0e6d73ebefbc26dddc11a47bcc12a3691aca7'
21 'SKIP')
22validpgpkeys=('757FAB7CED1814AE15B4836E5FB027474203454C') # Michael Busch
23
24build() {
25 cd razercfg-$pkgver
26 RAZERCFG_PKG_BUILD=1 cmake -DCMAKE_INSTALL_PREFIX=/usr .
27 cmake --build .
28}
29
30package() {
31 cd razercfg-$pkgver
32 RAZERCFG_PKG_BUILD=1 DESTDIR="$pkgdir" cmake --install .
33
34 install -Dm644 -t "$pkgdir"/etc razer.conf
35 install -Dm644 tmpfile.conf "$pkgdir"/usr/lib/tmpfiles.d/razerd.conf
36}
37

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion