sentinelx
The pip install commands are used to install build dependencies (including pyinstaller and requirements from the project's own source) during compilation, which is a normal part of building a Python application from source; the source is from the project's official repository and the final binary is self-contained.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install commands are used to install build dependencies (including pyinstaller and requirements from the project's own source) during compilation, which is a normal part of building a Python application from source; the source is from the project's official repository and the final binary is self-contained.
1 higher static finding superseded - not the current verdict (shown for transparency)
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:30
pip install --upgrade pip -
PKGBUILD:31
pip install -r requirements.txt -
PKGBUILD:32
pip install pyinstaller
PKGBUILD
3 offending line(s) highlighted# Maintainer: Daniel Serrano Armenta <anabasasoft@gmail.com>
pkgname=sentinelx
pkgver=1.4.5
pkgrel=1
pkgdesc="Tu Guardián de Red para Linux. Simple. Potente. Inteligente. (Compila desde fuente)"
arch=('x86_64')
url="https://github.com/AnabasaSoft/SentinelX"
license=('LGPL3')
provides=('sentinelx')
conflicts=('sentinelx' 'sentinelx-bin')
# Dependencias para EJECUTAR
depends=('python' 'polkit' 'clamav' 'hicolor-icon-theme')
# Dependencias necesarias solo para COMPILAR (Build)
makedepends=('git' 'python-pip' 'python-setuptools' 'base-devel')
# Descargamos el código fuente exacto de la versión
source=("git+https://github.com/AnabasaSoft/SentinelX.git#tag=v${pkgver}")
sha256sums=('5cdf4c42b8e4a8e5f2562213568fbf34ebafd1f9ba75e9b0243c91a03ea6b07f')
build() {
cd "SentinelX"
echo "📦 Creando entorno virtual temporal..."
python -m venv venv
source venv/bin/activate
echo "⬇️ Instalando dependencias..."
pip install --upgrade pip
pip install -r requirements.txt
pip install pyinstaller
echo "🔨 Compilando binario..."
# Usamos --onedir para que sea más rápido de arrancar en sistema
pyinstaller --noconfirm \
--onedir \
--windowed \
--name "SentinelX" \
--add-data "SentinelX-Icon-512.png:." \
--add-data "lang:lang" \
--hidden-import "PySide6" \
SentinelX.py
}
package() {
cd "SentinelX"
echo "📂 Instalando archivos en el sistema..."
# 1. Copiar la carpeta compilada a /opt
install -dm755 "${pkgdir}/opt/${pkgname}"
cp -r "dist/SentinelX/"* "${pkgdir}/opt/${pkgname}/"
# 2. Enlace simbólico
install -dm755 "${pkgdir}/usr/bin"
ln -s "/opt/${pkgname}/SentinelX" "${pkgdir}/usr/bin/${pkgname}"
# 3. Icono
install -Dm644 "SentinelX-Icon-512.png" "${pkgdir}/usr/share/icons/hicolor/512x512/apps/${pkgname}.png"
# 4. Desktop Entry
install -dm755 "${pkgdir}/usr/share/applications"
cat << EOF > "${pkgdir}/usr/share/applications/${pkgname}.desktop"
[Desktop Entry]
Name=SentinelX
Comment=Tu Guardián de Red para Linux
Exec=/usr/bin/${pkgname}
Icon=${pkgname}
Type=Application
Categories=System;Security;Network;
Terminal=false
EOF
# 5. Instalar licencia
install -Dm644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |