rlbotgui-rust-git
The cargo install is used to build the project's own Tauri application from its official GitHub repository, which is a normal part of the build process for Rust-based GUIs and does not constitute an external or untrusted dependency injection.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The cargo install is used to build the project's own Tauri application from its official GitHub repository, which is a normal part of the build process for Rust-based GUIs and does not constitute an external or untrusted dependency injection.
1 higher static finding superseded - not the current verdict (shown for transparency)
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:22
cargo install tauri-cli --version "^1.0.0"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Simon <contact at swz dot works>
pkgname=rlbotgui-rust-git
git_pkgname=rlbot_gui_rust
cargo_pkgname=rl-bot-gui
pkgver=1.0.8.2f61792
pkgrel=1
pkgdesc="A Rust GUI for the RLBot framework"
arch=("x86_64")
url="https://github.com/VirxEC/rlbot_gui_rust"
replaces=("rlbot-gui-rust-git")
depends=("python")
makedepends=("cargo" "git" "sed")
license=("custom")
source=("git+https://github.com/VirxEC/rlbot_gui_rust")
sha512sums=(SKIP)
build() {
cd "$srcdir/$git_pkgname/src-tauri"
cargo install tauri-cli --version "^1.0.0"
cargo tauri build
}
package() {
cd "$srcdir/$git_pkgname/src-tauri"
debdatapath="target/release/bundle/deb/${cargo_pkgname}_$(grep '^version =' Cargo.toml|head -n1|cut -d\" -f2|cut -d\- -f1)_amd64/data"
install -Dm755 "target/release/$cargo_pkgname" "${pkgdir}/usr/bin/$cargo_pkgname"
install -Dm755 "${debdatapath}/usr/share/applications/${cargo_pkgname}.desktop" "${pkgdir}/usr/share/applications/${cargo_pkgname}.desktop"
install -Dm755 "${debdatapath}/usr/share/icons/hicolor/192x192/apps/${cargo_pkgname}.png" "${pkgdir}/usr/share/icons/hicolor/192x192/apps/${cargo_pkgname}.png"
}
pkgver() {
cd "$srcdir/$git_pkgname/src-tauri"
echo "$(grep '^version =' Cargo.toml|head -n1|cut -d\" -f2|cut -d\- -f1).$(git rev-parse --short HEAD)"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |