secfetch

LOW
maintainer ake13-art 1 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The pip install is used to build the package from the project's own source tarball, which is hosted at the project's official GitHub repository and verified by a checksum; this is a normal and safe AUR packaging practice.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install is used to build the package from the project's own source tarball, which is hosted at the project's official GitHub repository and verified by a checksum; this is a normal and safe AUR packaging practice.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium pip install of an external package pip_install_external

`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:25 PIP_CONFIG_FILE=/dev/null pip install --isolated --root="${pkgdir}" --ignore-installed --no-warn-script-location --root-user-action ignore --no-deps .

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Rafael Dominiquini <rafaeldominiquini at gmail dot com>
2
3pkgname="secfetch"
4pkgver=1.7.0
5pkgrel=1
6pkgdesc="Lightweight security state inspector for Linux"
7
8license=('GPL-3.0')
9arch=('any')
10
11url="https://github.com/ake13-art/secfetch"
12
13provides=("${pkgname}")
14
15makedepends=('python-setuptools' 'python-wheel' 'python-build' 'python-installer' 'python-pip')
16depends=('python')
17
18source=("${pkgname}-${pkgver}.tgz::${url}/archive/refs/tags/v${pkgver}.tar.gz")
19sha256sums=('20da6a5b0926655286c127ec9ad2f6c7bed99a949c5b2eadc1f776a022206374')
20
21
22package() {
23 cd "${srcdir}/${pkgname}-${pkgver}/"
24
25 PIP_CONFIG_FILE=/dev/null pip install --isolated --root="${pkgdir}" --ignore-installed --no-warn-script-location --root-user-action ignore --no-deps .
26
27 python -O -m compileall "${pkgdir}"
28}
29

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion