timingeditor-svn
maintainer tanjiro.kamado
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source uses a Subversion checkout from a project-owned SourceForge URL, which is a normal AUR packaging practice despite the non-whitelisted host; the build compiles source code directly, and there is no execution of prebuilt or unverifiable binaries.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source uses a Subversion checkout from a project-owned SourceForge URL, which is a normal AUR packaging practice despite the non-whitelisted host; the build compiles source code directly, and there is no execution of prebuilt or unverifiable binaries.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:21
'timingeditor-svn::svn+https://svn.code.sf.net/p/timingeditor/code/trunk'
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Tanjiro Kamado <tanjiro.kamado at yandex dot com>
2
pkgname=timingeditor-svn
3
_pkgN=timingeditor
4
_ccn=TimingEditor
5
pkgver=r115
6
pkgrel=1
7
pkgdesc="The Timing Editor is a free tool to draw timing diagrams. "
8
arch=('x86_64')
9
url="http://timingeditor.sourceforge.net"
10
license=('GPL2')
11
groups=()
12
depends=('wxgtk')
13
makedepends=('subversion')
14
provides=("timingeditor")
15
conflicts=("timingeditor")
16
replaces=()
17
backup=()
18
options=()
19
install=
20
source=(
21
'timingeditor-svn::svn+https://svn.code.sf.net/p/timingeditor/code/trunk'
22
"wx3.patch"
23
)
24
noextract=()
25
sha256sums=(
26
'SKIP'
27
'cc0e4f8b477e59185b4d5dd58fef3de4eb48ebdcdddd136aeffa8a28c326cfbb'
28
)
29
30
31
pkgver() {
32
cd "$srcdir/${pkgname}"
33
printf "r%s" "$(svnversion | tr -d 'A-z')"
34
}
35
36
prepare() {
37
cd "$srcdir/${pkgname}"
38
patch -p1 -i "$srcdir/wx3.patch"
39
#sed -i s/\#include \<wx/svg/dcsvg.h\>/\#include \<wx\/dcsvg.h\>/g TimingView.cpp
40
#sed -i s/wxCMD_LINE_PARAM, NULL, NULL, _T\(\"input file\"\)/wxCMD_LINE_PARAM, NULL, NULL, wxT_2\(\"input file\"\)/g TimingApp.cpp
41
42
}
43
44
build() {
45
cd "$srcdir/${pkgname}"
46
g++ *.cpp -DNDEBUG `wx-config --cxxflags --libs std,aui` -o $_ccn
47
}
48
49
50
package() {
51
_base="$pkgdir/usr/bin"
52
cd "$srcdir/${pkgname}"
53
54
mkdir -p "$_base/$_ccn"
55
cp "$_ccn" "$_base/$_ccn/"
56
rm -rf art/.svn
57
cp -r art "$_base/$_ccn/"
58
cd "$_base"
59
ln -s "$_ccn/$_ccn" "$_pkgN"
60
}
61
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |