studio-controls-git

LOW
maintainer milkii 8 votes scanned 2026-10-03 00:23:04.761738
View on AUR
Why flagged

The pip install fetches a non-executable Python module (pyalsaaudio) as a build-time dependency; while external, it is a known package and the action occurs in a controlled, isolated environment during packaging, not at runtime.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The pip install fetches a non-executable Python module (pyalsaaudio) as a build-time dependency; while external, it is a known package and the action occurs in a controlled, isolated environment during packaging, not at runtime.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium pip install of an external package pip_install_external

`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:62 PIP_CONFIG_FILE=/dev/null pip install --isolated --root="$pkgdir" --ignore-installed --no-deps pyalsaaudio

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Milk Brewster (milkii on freenode)
2# Maintainer: David Marzal <mundolibre at tutanota dot com>
3
4_pkgname=studio-controls
5pkgname=${_pkgname}-git
6pkgver=2.3.9.r2.g83c2bc7
7pkgrel=1
8pkgdesc="An JACK audio setup utility with USB device and PulseAudio bridges."
9arch=('x86_64')
10url="https://github.com/ovenwerks/studio-controls"
11license=('GPL-2.0-only')
12groups=()
13depends=('jack2' 'jack2-dbus' 'python' 'python-gobject' 'python-dbus' 'python-jack-client' 'zita-ajbridge' 'a2jmidid')
14makedepends=(git python-pip alsa-lib)
15optdepends=('pulseaudio-jack: PulseAudio to JACK bridge'
16 'alsa-utils: ALSA - Utilities (amixer)'
17 'libffado: Driver for FireWire audio devices'
18 'realtime-privileges: Realtime privileges for users'
19 'carla: Audio Plugin Host'
20 'pavucontrol: PulseAudio Volume Control'
21 'qastools: qasmixer desktop mixer application'
22 'agordejo: NSM based music production session manager'
23 'raysession: NSM based music production session manager'
24 'new-session-manager: NSM server and reference GUI'
25 'zita-mu1: JACK app used to organise stereo monitoring')
26provides=('studio-controls' 'studio-controls-git')
27conflicts=('studio-controls' 'studio-controls-git' 'cadence')
28replaces=()
29backup=()
30options=()
31#install="${_pkgname}.install"
32source=('git+https://github.com/ovenwerks/studio-controls')
33noextract=()
34md5sums=('SKIP')
35
36pkgver() {
37 cd "$srcdir/${_pkgname%}"
38 ( set -o pipefail
39 git describe --long --tags 2>/dev/null | sed 's/\([^-]*-g\)/r\1/;s/-/./g' ||
40 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
41 )
42}
43
44prepare() {
45 cd "$srcdir/${_pkgname%}"
46}
47
48build() {
49 cd "$srcdir/${_pkgname%}"
50}
51
52check() {
53 cd "$srcdir/${_pkgname%}"
54}
55
56package() {
57 cd "$srcdir/${_pkgname%}"
58 cp -r etc usr $pkgdir
59 mv $pkgdir/usr/sbin/studio-system $pkgdir/usr/bin
60 rm -rf $pkgdir/usr/sbin
61 # Install pyalsaaudio via pip (not in official repos)
62 PIP_CONFIG_FILE=/dev/null pip install --isolated --root="$pkgdir" --ignore-installed --no-deps pyalsaaudio
63}
64

Scan history

Scanned at (UTC)SeverityRules
2026-10-03 00:23:04 Low 2
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 07:16:35 Medium 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion