studio-controls-git
The pip install fetches a non-executable Python module (pyalsaaudio) as a build-time dependency; while external, it is a known package and the action occurs in a controlled, isolated environment during packaging, not at runtime.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install fetches a non-executable Python module (pyalsaaudio) as a build-time dependency; while external, it is a known package and the action occurs in a controlled, isolated environment during packaging, not at runtime.
1 higher static finding superseded - not the current verdict (shown for transparency)
pip_install_external
`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:62
PIP_CONFIG_FILE=/dev/null pip install --isolated --root="$pkgdir" --ignore-installed --no-deps pyalsaaudio
PKGBUILD
1 offending line(s) highlighted# Maintainer: Milk Brewster (milkii on freenode)
# Maintainer: David Marzal <mundolibre at tutanota dot com>
_pkgname=studio-controls
pkgname=${_pkgname}-git
pkgver=2.3.9.r2.g83c2bc7
pkgrel=1
pkgdesc="An JACK audio setup utility with USB device and PulseAudio bridges."
arch=('x86_64')
url="https://github.com/ovenwerks/studio-controls"
license=('GPL-2.0-only')
groups=()
depends=('jack2' 'jack2-dbus' 'python' 'python-gobject' 'python-dbus' 'python-jack-client' 'zita-ajbridge' 'a2jmidid')
makedepends=(git python-pip alsa-lib)
optdepends=('pulseaudio-jack: PulseAudio to JACK bridge'
'alsa-utils: ALSA - Utilities (amixer)'
'libffado: Driver for FireWire audio devices'
'realtime-privileges: Realtime privileges for users'
'carla: Audio Plugin Host'
'pavucontrol: PulseAudio Volume Control'
'qastools: qasmixer desktop mixer application'
'agordejo: NSM based music production session manager'
'raysession: NSM based music production session manager'
'new-session-manager: NSM server and reference GUI'
'zita-mu1: JACK app used to organise stereo monitoring')
provides=('studio-controls' 'studio-controls-git')
conflicts=('studio-controls' 'studio-controls-git' 'cadence')
replaces=()
backup=()
options=()
#install="${_pkgname}.install"
source=('git+https://github.com/ovenwerks/studio-controls')
noextract=()
md5sums=('SKIP')
pkgver() {
cd "$srcdir/${_pkgname%}"
( set -o pipefail
git describe --long --tags 2>/dev/null | sed 's/\([^-]*-g\)/r\1/;s/-/./g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
)
}
prepare() {
cd "$srcdir/${_pkgname%}"
}
build() {
cd "$srcdir/${_pkgname%}"
}
check() {
cd "$srcdir/${_pkgname%}"
}
package() {
cd "$srcdir/${_pkgname%}"
cp -r etc usr $pkgdir
mv $pkgdir/usr/sbin/studio-system $pkgdir/usr/bin
rm -rf $pkgdir/usr/sbin
# Install pyalsaaudio via pip (not in official repos)
PIP_CONFIG_FILE=/dev/null pip install --isolated --root="$pkgdir" --ignore-installed --no-deps pyalsaaudio
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 07:16:35 | Medium | 1 |