super-slomo-git

maintainer aviallon · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The non-standard host provides a model checkpoint file (non-executable data), not code, and the source code is from a legitimate fork of the project; worst case is model tampering, not code execution.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host provides a model checkpoint file (non-executable data), not code, and the source code is from a legitimate fork of the project; worst case is model tampering, not code execution.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 "https://ftp.lesviallon.fr/other/SuperSloMo.ckpt"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Antoine Viallon <antoine+aur@lesviallon.fr>
2pkgname=super-slomo-git
3_pkgname=super-slomo
4pkgver=r65.2ebebc7
5pkgrel=1
6license=('MIT')
7pkgdesc='PyTorch implementation of "Super SloMo: High Quality Estimation of Multiple Intermediate Frames for Video Interpolation"'
8depends=("python-torchvision")
9arch=("x86_64")
10url='https://github.com/avinashpaliwal/Super-SloMo'
11source=("$pkgname::git+https://github.com/aviallon/Super-SloMo.git#branch=dev"
12 "https://ftp.lesviallon.fr/other/SuperSloMo.ckpt"
13 "super-slomo")
14sha256sums=('SKIP'
15 '1931f099a99e5e65a563f9b3aae0e04b6d87d09a0c85be1f761185c6bc67506e'
16 'f8d6878dd33fd37cdb0748a1d556de307f4e9b3469af722c6ab7997d63cfaaaa')
17
18
19pkgver() {
20 cd "$pkgname"
21 ( set -o pipefail
22 git describe --long 2>/dev/null | sed 's/\([^-]*-g\)/r\1/;s/-/./g' ||
23 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
24 )
25}
26
27prepare() {
28 cd "$srcdir/$pkgname"
29
30 for patch in $(cd $srcdir && ls *.patch); do
31 patch --verbose -p1 < "$srcdir/$patch"
32 done
33}
34
35package() {
36 cd "$pkgname"
37
38 install -v -Dm644 "$srcdir/SuperSloMo.ckpt" "$pkgdir"/usr/share/"$_pkgname"/model/SuperSloMo.ckpt
39
40 for file in "$srcdir/$pkgname/"*.py; do
41 install -v -Dm644 "$file" "$pkgdir"/usr/share/"$_pkgname"/
42 done
43
44 install -v -Dm755 "$srcdir/super-slomo" "$pkgdir"/usr/bin/super-slomo
45}
46

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion