sotw-dev

LOW
maintainer Larzid 1 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads source code from GitHub and assets from the project's official website; both are legitimate project resources, with the assets being non-executable data, so the risk from the non-standard host is minimal.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads source code from GitHub and assets from the project's official website; both are legitimate project resources, with the assets being non-executable data, so the risk from the non-standard host is minimal.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:21 source=('git+https://github.com/prolog/shadow-of-the-wyrm.git' 'https://www.shadowofthewyrm.org/assets/ShadowOfTheWyrm-assets.zip')

PKGBUILD

1 offending line(s) highlighted
1#Maintainer: Larzid <juanitocampamocha@gmail.com>
2pkgname=sotw-dev
3pkgver=development
4pkgrel=18
5epoch=
6pkgdesc="Shadow Of The Wyrm by Julian Day - Development branch."
7arch=('x86_64')
8url="http://www.shadowofthewyrm.org/"
9license=('MIT')
10groups=()
11depends=('sdl2' 'sdl2_mixer' 'sdl2_image' 'xerces-c' 'zlib' 'ncurses' 'lua51' 'boost' 'gtest')
12makedepends=('premake' 'git')
13checkdepends=()
14provides=(sotw)
15conflicts=(sotw)
16replaces=()
17backup=()
18options=()
19install=post.install
20changelog=
21source=('git+https://github.com/prolog/shadow-of-the-wyrm.git' 'https://www.shadowofthewyrm.org/assets/ShadowOfTheWyrm-assets.zip')
22noextract=()
23md5sums=('SKIP' '57c5bbb8ea28e09b71e0c6b426205988')
24validpgpkeys=()
25
26build() {
27 cd shadow-of-the-wyrm
28 git checkout develop
29 cp -R ../assets ./
30 premake5 --lua_include=/usr/include/lua5.1 --lua_link=lua5.1 gmake
31 make config=release
32 #make config=debug
33}
34
35package() {
36# Create launch script
37 echo "#!/bin/bash" > ${srcdir}/shadow-of-the-wyrm/sotw.sh
38 echo "cd /usr/share/sotw" >> ${srcdir}/shadow-of-the-wyrm/sotw.sh
39 echo "./sotw" >> ${srcdir}/shadow-of-the-wyrm/sotw.sh
40 chmod +x ${srcdir}/shadow-of-the-wyrm/sotw.sh
41
42# Create the .desktop entry.
43 echo "[Desktop Entry]
44 Version=$pkgver
45 Name=Shadow Of The Wyrm
46 GenericName=SOTW
47 Type=Application
48 Comment=A single player, traditional roguelike by Julian Day.
49 Icon=sotw_icon
50 Exec=sotw
51 Terminal=false
52 SartupNotify=false
53 Keywords=game;roguelike;
54 Categories=Game;" > ${srcdir}/sotw.desktop
55
56# Tweak game settings.
57 # Setup log directory.
58 sed -i '16s|.*|log_dir=/var/sotw/log|' ${srcdir}/shadow-of-the-wyrm/swyrm.ini
59 mkdir ${pkgdir}/var
60 mkdir ${pkgdir}/var/sotw
61 mkdir ${pkgdir}/var/sotw/log
62 chmod -R 777 ${pkgdir}/var/sotw
63 # Set system dump directory.
64 sed -i '39s|.*|syschardump_dir=/var/sotw|' ${srcdir}/shadow-of-the-wyrm/swyrm.ini
65 # Set score file location.
66 sed -i '49s|.*|scorefile_dir=/var/sotw|' ${srcdir}/shadow-of-the-wyrm/swyrm.ini
67 # Set disallow score for narrative mode and console commands.
68 sed -i '636s|.*|_disallow_score_on_exploration=1|' ${srcdir}/shadow-of-the-wyrm/swyrm.ini
69
70# Do the actual packaging
71 install -D -m644 ${srcdir}/shadow-of-the-wyrm/LICENSE "${pkgdir}/usr/share/licenses/sotw/LICENSE"
72 # install -d -m777 ${srcdir}/shadow-of-the-wyrm/sotw "${pkgdir}/usr/share/sotw"
73 install -d ${srcdir}/shadow-of-the-wyrm/sotw "${pkgdir}/usr/share/sotw"
74 install -D ${srcdir}/shadow-of-the-wyrm/sotw/sotw "${pkgdir}/usr/share/sotw/sotw"
75 install -D ${srcdir}/shadow-of-the-wyrm/howdoi.txt "${pkgdir}/usr/share/sotw/howdoi.txt"
76 install -D ${srcdir}/shadow-of-the-wyrm/LICENSE "${pkgdir}/usr/share/sotw/LICENSE"
77 install -D ${srcdir}/shadow-of-the-wyrm/README.md "${pkgdir}/usr/share/sotw/README.md"
78 install -D ${srcdir}/shadow-of-the-wyrm/shadowofthewyrmtext_blank.ini "${pkgdir}/usr/share/sotw/shadowofthewyrmtext_blank.ini"
79 install -D ${srcdir}/shadow-of-the-wyrm/shadowofthewyrmtext_en.ini "${pkgdir}/usr/share/sotw/shadowofthewyrmtext_en.ini"
80 install -D ${srcdir}/shadow-of-the-wyrm/swyrm.ini "${pkgdir}/usr/share/sotw/swyrm.ini"
81 cp -R ${srcdir}/shadow-of-the-wyrm/assets ${pkgdir}/usr/share/sotw/assets
82 cp -R ${srcdir}/shadow-of-the-wyrm/sotw/data ${pkgdir}/usr/share/sotw/data
83 cp -R ${srcdir}/shadow-of-the-wyrm/sotw/docs ${pkgdir}/usr/share/sotw/docs
84 cp -R ${srcdir}/shadow-of-the-wyrm/sotw/licenses ${pkgdir}/usr/share/sotw/licenses
85 cp -R ${srcdir}/shadow-of-the-wyrm/sotw/logs ${pkgdir}/usr/share/sotw/logs
86 cp -R ${srcdir}/shadow-of-the-wyrm/sotw/scripts ${pkgdir}/usr/share/sotw/scripts
87 cp -R ${srcdir}/shadow-of-the-wyrm/sotw/texts ${pkgdir}/usr/share/sotw/texts
88 mkdir ${pkgdir}/usr/share/icons/
89 mkdir ${pkgdir}/usr/share/applications/
90 cp -R ${srcdir}/shadow-of-the-wyrm/sotw_icon.ico ${pkgdir}/usr/share/icons/sotw_icon.png
91 cp -R ${srcdir}/sotw.desktop ${pkgdir}/usr/share/applications/sotw.desktop
92 install -D ${srcdir}/shadow-of-the-wyrm/sotw.sh ${pkgdir}/usr/bin/sotw
93}
94

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion