strength-tracker-rs
The package builds from source via a git checkout of the project's own GitHub repository; the SKIP'd checksum and low votes are quality concerns but do not indicate active danger as no untrusted prebuilt binaries or remote code execution are involved.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from source via a git checkout of the project's own GitHub repository; the SKIP'd checksum and low votes are quality concerns but do not indicate active danger as no untrusted prebuilt binaries or remote code execution are involved.
PKGBUILD
pkgname=strength-tracker-rs
pkgver=3.0.0
pkgrel=1
pkgdesc='Sync your devices and track your strength training'
arch=('x86_64')
url="https://github.com/Emiliopg91/${pkgname}"
license=('GPL-2')
source=(
"git+$url.git#tag=$pkgver"
)
sha256sums=(
'SKIP'
)
depends=('webkit2gtk-4.1' 'zlib-ng-compat')
makedepends=('mold' 'npm' 'pnpm' 'python-toml' 'python-yaml' 'rust' 'sccache')
conflicts=('garmin-tracker-rs')
replaces=('garmin-tracker-rs')
install=${pkgname}.install
build() {
cd "$srcdir/${pkgname}"
export RUSTC_WRAPPER=sccache
export CARGO_BUILD_JOBS=$(nproc)
if [ -z "$GITHUB_ACTIONS" ] && [ -z "$CI" ]; then
export RUSTFLAGS="-C target-cpu=native -C link-arg=-fuse-ld=mold"
else
export RUSTFLAGS="-C link-arg=-fuse-ld=mold"
fi
make build
}
package() {
cd "$srcdir/${pkgname}/src-tauri/target/release/bundle/deb"
cp -a Strength\ Tracker_${pkgver}_*/data/* "${pkgdir}"
cd "$srcdir/${pkgname}/resources"
install -Dm555 strength-tracker-rs-launcher.sh "$pkgdir/usr/share/strength-tracker-rs/strength-tracker-rs-launcher.sh"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-08 14:08:57 | Low | 2 |