spritz-bin
The package downloads prebuilt binaries from GitHub releases, which is a supply-chain risk if the host is compromised, but the binaries are from the project's official repository and checksums are provided, limiting the risk to typical AUR binary package concerns.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads prebuilt binaries from GitHub releases, which is a supply-chain risk if the host is compromised, but the binaries are from the project's official repository and checksums are provided, limiting the risk to typical AUR binary package concerns.
PKGBUILD
# Maintainer: Rafael Dominiquini <rafaeldominiquini at gmail dot com>
_gitauthor=dfallman
_gitname=spritz
_appname=${_gitname}
pkgname=${_appname}-bin
pkgdesc="A multiplatform, nano DLNA media server for the terminal"
pkgver=0.2.0
pkgrel=1
_gitversion=v${pkgver}
arch=('x86_64' 'aarch64')
_barch=('x86_64-unknown-linux-gnu' 'aarch64-unknown-linux-gnu')
_ghurl="https://github.com/${_gitauthor}/${_gitname}"
_ghurlraw="https://raw.githubusercontent.com/${_gitauthor}/${_gitname}/${_gitversion}"
url=${_ghurl}
license=('MIT')
provides=("${_appname}")
conflicts=("${pkgname%-bin}")
depends=('glibc' 'libgcc')
options=('!strip')
source_x86_64=("${_appname}-${arch[0]}-${pkgver}.txz::${_ghurl}/releases/download/${_gitversion}/${_appname}-${_barch[0]}.tar.xz")
source_aarch64=("${_appname}-${arch[1]}-${pkgver}.txz::${_ghurl}/releases/download/${_gitversion}/${_appname}-${_barch[1]}.tar.xz")
sha256sums_x86_64=('48261875d49772d86b11bbc8adbdd95434cfb7a8612eb8fbf27a343cf23b45f4')
sha256sums_aarch64=('29ff8f0ce4619b70d82a1abcaf0c9d6cc77d0c332ddd7299d3e1849aaca28860')
case ${CARCH} in
${arch[0]})
_CARCH=${_barch[0]}
;;
${arch[1]})
_CARCH=${_barch[1]}
;;
esac
package() {
cd "${srcdir}/${_appname}-${_CARCH}/" || exit
install -Dm755 "${_appname}" "${pkgdir}/usr/bin/${_appname}"
install -Dm644 "README.md" "${pkgdir}/usr/share/doc/${pkgname}/README.md"
install -Dm644 "LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:13:36 | Low | 2 |
| 2026-10-05 23:40:58 | Low | 1 |