tinmop-git
The package downloads sources from non-whitelisted hosts, but they are part of the project's normal build process: a git repository, Quicklisp Lisp installer (used to fetch dependencies in a sandbox), and a referenced git submodule; all are used to build the software from source, not to run untrusted prebuilt binaries or exfiltrate data.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads sources from non-whitelisted hosts, but they are part of the project's normal build process: a git repository, Quicklisp Lisp installer (used to fetch dependencies in a sandbox), and a referenced git submodule; all are used to build the software from source, not to run untrusted prebuilt binaries or exfiltrate data.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
'https://beta.quicklisp.org/quicklisp.lisp'
PKGBUILD
1 offending line(s) highlighted
# Maintainer: Andrea Feletto <andrea@andreafeletto.com>
pkgname=tinmop-git
_pkgname=${pkgname%-*}
pkgver=v0.9.2.r179.g662ff56
pkgrel=1
pkgdesc='Opinionated TUI client for gemini, pleroma and kami'
arch=('x86_64')
url='https://www.autistici.org/interzona/tinmop.html'
license=('GPL3')
depends=('openssl' 'sbcl' 'unzip')
makedepends=('git' 'gettext' 'sbcl')
source=(
"git+https://notabug.org/cage/$_pkgname.git"
'https://beta.quicklisp.org/quicklisp.lisp'
'https://beta.quicklisp.org/quicklisp.lisp.asc'
'git+https://github.com/McParen/croatoan'
)
sha256sums=('SKIP' 'SKIP' 'SKIP' 'SKIP')
validpgpkeys=('D7A3489DDEFE32B7D0E7CC61307965AB028B5FF7')
options=('!strip')
prepare() {
cd "$srcdir"
commit_hash=$(grep CROATOAN_COMMIT= "$_pkgname/quick_quicklisp.sh.in")
commit_hash=$(printf '%s\n' "$commit_hash" | cut -d= -f2)
cd "$srcdir/croatoan"
git checkout "$commit_hash"
}
pkgver() {
cd "$srcdir/$_pkgname"
git describe --long | sed 's/-/.r/;s/-/./'
}
_install_lisp_deps() {
cd "$srcdir"
sbcl_args=''
if [ -r "quicklisp/setup.lisp" ]; then
sbcl_args="$sbcl_args --load quicklisp/setup.lisp"
else
sbcl_args="$sbcl_args --load quicklisp.lisp"
sbcl_args="$sbcl_args --eval \
'(quicklisp-quickstart:install :path \"quicklisp\")'"
fi
while read -r dep; do
sbcl_args="$sbcl_args --eval '(ql:quickload \"$dep\")'"
done < "$_pkgname/lisp-dependencies"
sbcl_args="$sbcl_args --eval '(sb-ext:quit)'"
eval "sbcl --no-userinit $sbcl_args"
ln -sft quicklisp/local-projects "$srcdir/croatoan"
printf '(load "%s/quicklisp/setup.lisp")' "$srcdir" > sbclrc
}
build() {
_install_lisp_deps
cd "$srcdir/$_pkgname"
autoreconf -fiv
./configure --prefix='/usr' --sysconfdir='/etc'
sed -i "s%LISP_COMPILER = .*%LISP_COMPILER = sbcl \
--userinit '$srcdir/sbclrc'%" Makefile
make
}
package() {
cd "$srcdir/$_pkgname"
make DESTDIR="$pkgdir/" install
install -Dm644 LICENSES.org -t "$pkgdir/usr/share/licenses/$_pkgname"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |