rozelynx-git

LOW
maintainer burningserenity 0 votes scanned 2026-10-08 20:09:40.002650
View on AUR
Why flagged

The package builds from a pinned, publicly accessible Git repository and uses a SKIP'd checksum only for the source Git clone, which is normal for -git packages; the actual build inputs are version-pinned in a config file, and no untrusted binaries or remote code execution are involved.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from a pinned, publicly accessible Git repository and uses a SKIP'd checksum only for the source Git clone, which is normal for -git packages; the actual build inputs are version-pinned in a config file, and no untrusted binaries or remote code execution are involved.

PKGBUILD

1# Maintainer: burningserenity <burningserenity@novo-ordo.com>
2
3# RozeLynx built from source via the distro-agnostic build script
4# (rozelynx-distro-build.sh): fetch -> prepare -> configure -> build ->
5# install, then the staged /usr tree is copied into the package.
6# Everything is pinned in rozelynx-distro-versions.conf; pkgver tracks the
7# pinned FIREFOX_VERSION plus the git revision.
8#
9# This is a full Firefox build: ~10-19 GB of disk, several hours of compile
10# time, and pinned downloads at build time (Firefox source tarball,
11# Gentoo patchset, LibreWolf/Floorp reference checkouts).
12
13pkgname=rozelynx-git
14pkgver=156.0.1.r6.ge28dc3a
15pkgrel=1
16pkgdesc='RozeLynx Web Browser: Firefox fork with LibreWolf privacy patches and per-tab network interface binding'
17arch=(x86_64 aarch64)
18url='https://bytewheel.org/rozelynx'
19license=('MPL-2.0' 'GPL-2.0-only' 'LGPL-2.1-only')
20depends=(
21 alsa-lib
22 aom
23 at-spi2-core
24 cairo
25 dav1d
26 dbus
27 ffmpeg
28 fontconfig
29 freetype2
30 gdk-pixbuf2
31 glib2
32 gtk3
33 harfbuzz
34 'icu>=78.1'
35 libdrm
36 libepoxy
37 libevent
38 libjpeg-turbo
39 libpulse
40 libvpx
41 libwebp
42 libx11
43 libxcb
44 libxcomposite
45 libxdamage
46 libxext
47 libxfixes
48 libxrandr
49 mesa
50 'nspr>=4.39'
51 'nss>=3.125'
52 pango
53 pixman
54 zlib
55)
56makedepends=(
57 clang
58 curl
59 git
60 imagemagick
61 lld
62 nasm
63 nodejs
64 pkgconf
65 'python>=3.12'
66 'rust>=1.90'
67 zip
68)
69optdepends=(
70 'libva: VAAPI hardware video decoding'
71 'networkmanager: geolocation via nearby Wi-Fi networks (necko-wifi)'
72 'vulkan-icd-loader: Vulkan rendering (hwaccel vulkantest)'
73)
74provides=("rozelynx=${pkgver%.r*}")
75conflicts=(rozelynx)
76install=rozelynx-git.install
77source=("${pkgname}::git+https://github.com/Bytewheel/RozeLynx.git#branch=main")
78sha256sums=('SKIP')
79
80pkgver() {
81 cd "${srcdir}/${pkgname}"
82 local ffver
83 ffver="$(sed -n 's/^FIREFOX_VERSION="\([^"]*\)".*/\1/p' rozelynx-distro-versions.conf)"
84 printf '%s.r%s.g%s' "${ffver}" \
85 "$(git rev-list --count HEAD)" \
86 "$(git rev-parse --short HEAD)"
87}
88
89build() {
90 cd "${srcdir}/${pkgname}"
91
92 # all = fetch prepare configure build install; the install stage leaves a
93 # complete /usr tree (launcher, browser, extension XPI, prefs, desktop
94 # file, icons, native messaging host) under <workdir>/stage/.
95 # Feature flags match the Gentoo ebuild USE defaults; override with
96 # --use/--no-use, e.g. ./rozelynx-distro-build.sh --no-use net-iface all
97 ./rozelynx-distro-build.sh all \
98 --prefix /usr --libdir lib \
99 --workdir "${srcdir}/rozelynx-distro-build"
100}
101
102package() {
103 cp -a "${srcdir}/rozelynx-distro-build/stage/usr" "${pkgdir}/"
104}

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 20:09:40 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion