skychart
maintainer oldherl
· 3 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a beta version tarball hosted by the maintainer because upstream deletes beta releases; it is not a prebuilt binary or executable payload, and the package builds from source with a provided checksum, posing low risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a beta version tarball hosted by the maintainer because upstream deletes beta releases; it is not a prebuilt binary or executable payload, and the package builds from source with a provided checksum, posing low risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
"https://build.archlinuxcn.org/~oldherl/files/skychart/skychart-${_pkgver}-src.tar.xz"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: oldherl <oldherl@gmail.com>
2
3
pkgname=skychart
4
_pkgver=4.3-4991
5
pkgver=${_pkgver/-/.}
6
pkgrel=2
7
pkgdesc="Free software to draw sky charts, also known as Cartes du Ciel. Beta version"
8
arch=('x86_64')
9
license=('GPL-2.0-or-later')
10
depends=('qt6-base' 'xplanet' 'libpasastro' 'qt6pas')
11
makedepends=('fpc' 'lazarus-qt6' 'wget')
12
optdepends=(
13
"xplanet: for displaying textures on planets"
14
)
15
url="http://www.ap-i.net/skychart/start"
16
17
# Using my own copy of source code because upstream deletes beta tarballs regularly.
18
source=(
19
"https://build.archlinuxcn.org/~oldherl/files/skychart/skychart-${_pkgver}-src.tar.xz"
20
)
21
22
sha256sums=('2d58f801872804b75ac7df3d585a447023768cce7fab8817602f3eea4f066906')
23
24
prepare() {
25
cd "skychart-$_pkgver-src"
26
# Do not strip binaries when installing. Let makepkg do so.
27
# makepkg will produce a -debug package of the debug symbols.
28
sed -i 's/-m 755 -s/-m 755/g' install.sh
29
}
30
31
build() {
32
cd "skychart-$_pkgver-src"
33
fpc="/usr/lib/fpc/""`fpc -iV`""/units/x86_64-linux/"
34
echo fpc=$fpc
35
# Keep debug symbols and do not strip
36
export fpcopts="-g -gl -O3 -CX -XX"
37
echo fpcopts="$fpcopts"
38
echo ./configure fpc="$fpc" lazarus=/usr/lib/lazarus prefix="$pkgdir/usr" target=x86_64-linux
39
./configure fpc="$fpc" lazarus=/usr/lib/lazarus prefix="$pkgdir/usr" target=x86_64-linux
40
make CPU_TARGET=x86_64 OS_TARGET=linux LCL_PLATFORM=qt6 clean
41
make CPU_TARGET=x86_64 OS_TARGET=linux LCL_PLATFORM=qt6 -j 1
42
}
43
44
package() {
45
cd "skychart-$_pkgver-src"
46
echo pkgdir $pkgdir
47
mkdir -p "$pkgdir/usr"
48
make install
49
make install_data
50
make install_doc
51
make install_nonfree
52
}
53
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |