stardb-exporter-git

LOW
maintainer Arimil 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package builds from the project's own Git repository, disables self-updates via source patching, and installs a binary with necessary capabilities; the only risk is the unverifiable source due to SKIP'd checksum, but it is not executing remote code or downloading untrusted binaries.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from the project's own Git repository, disables self-updates via source patching, and installs a binary with necessary capabilities; the only risk is the unverifiable source due to SKIP'd checksum, but it is not executing remote code or downloading untrusted binaries.

PKGBUILD

1# Maintainer: Arimil <renari at arimil dot com>
2pkgname=stardb-exporter-git
3pkgver=r224.8ae5bfa
4pkgrel=1
5pkgdesc="A Hoyoverse exporter for pulls and achievements"
6arch=('x86_64')
7url="https://github.com/juliuskreutz/stardb-exporter"
8license=()
9# The GUI loads X11, Wayland, keyboard and GL libraries dynamically.
10depends=('glibc' 'libgcc' 'libpcap' 'libcap' 'libx11' 'libxcb'
11 'libxcursor' 'libxi' 'libxkbcommon' 'libxkbcommon-x11'
12 'wayland' 'libglvnd' 'xdg-utils')
13optdepends=('xdg-desktop-portal: native file dialogs (requires a desktop portal backend)')
14makedepends=('git' 'cargo' 'openssl')
15install=stardb-exporter.install
16source=("git+$url.git")
17sha256sums=('SKIP')
18# ring's C objects cannot use makepkg's GCC LTO with Rust's linker.
19options=('!lto')
20provides=('stardb-exporter')
21conflicts=('stardb-exporter')
22
23pkgver() {
24 cd "$srcdir/stardb-exporter"
25 echo "r$(git rev-list --count HEAD).$(git rev-parse --short HEAD)"
26}
27
28prepare() {
29 cd "$srcdir/stardb-exporter"
30 # Use the upstream debug-mode startup path in release builds: no self-update.
31 # Fail if upstream changes the expected configuration guards.
32 [[ $(grep -Fc '#[cfg(not(debug_assertions))]' src/app.rs) -eq 5 ]] || return 1
33 [[ $(grep -Fc '#[cfg(debug_assertions)]' src/app.rs) -eq 1 ]] || return 1
34 sed -i \
35 -e 's/#\[cfg(not(debug_assertions))\]/#[cfg(any())]/g' \
36 -e '/#\[cfg(debug_assertions)\]/d' \
37 -e 's/state: State::Waiting(.*),/state: State::Menu,/' \
38 src/app.rs
39 cargo fetch --locked --target "$CARCH-unknown-linux-gnu"
40}
41
42build() {
43 cd "$srcdir/stardb-exporter"
44 cargo build --release --frozen --features pcap --target-dir target
45}
46
47package() {
48 cd "$srcdir/stardb-exporter"
49 install -Dm755 "target/release/stardb-exporter" "$pkgdir/usr/bin/stardb-exporter"
50}
51

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion