tinmop-git
maintainer orphaned
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads sources from non-whitelisted hosts, but they are part of the project's normal build process: a git repository, Quicklisp Lisp installer (used to fetch dependencies in a sandbox), and a referenced git submodule; all are used to build the software from source, not to run untrusted prebuilt binaries or exfiltrate data.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads sources from non-whitelisted hosts, but they are part of the project's normal build process: a git repository, Quicklisp Lisp installer (used to fetch dependencies in a sandbox), and a referenced git submodule; all are used to build the software from source, not to run untrusted prebuilt binaries or exfiltrate data.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
'https://beta.quicklisp.org/quicklisp.lisp'
PKGBUILD
1 offending line(s) highlighted
1
2
# Maintainer: Andrea Feletto <andrea@andreafeletto.com>
3
4
pkgname=tinmop-git
5
_pkgname=${pkgname%-*}
6
pkgver=v0.9.2.r179.g662ff56
7
pkgrel=1
8
pkgdesc='Opinionated TUI client for gemini, pleroma and kami'
9
arch=('x86_64')
10
url='https://www.autistici.org/interzona/tinmop.html'
11
license=('GPL3')
12
depends=('openssl' 'sbcl' 'unzip')
13
makedepends=('git' 'gettext' 'sbcl')
14
source=(
15
"git+https://notabug.org/cage/$_pkgname.git"
16
'https://beta.quicklisp.org/quicklisp.lisp'
17
'https://beta.quicklisp.org/quicklisp.lisp.asc'
18
'git+https://github.com/McParen/croatoan'
19
)
20
sha256sums=('SKIP' 'SKIP' 'SKIP' 'SKIP')
21
validpgpkeys=('D7A3489DDEFE32B7D0E7CC61307965AB028B5FF7')
22
options=('!strip')
23
24
prepare() {
25
cd "$srcdir"
26
27
commit_hash=$(grep CROATOAN_COMMIT= "$_pkgname/quick_quicklisp.sh.in")
28
commit_hash=$(printf '%s\n' "$commit_hash" | cut -d= -f2)
29
30
cd "$srcdir/croatoan"
31
git checkout "$commit_hash"
32
}
33
34
pkgver() {
35
cd "$srcdir/$_pkgname"
36
git describe --long | sed 's/-/.r/;s/-/./'
37
}
38
39
_install_lisp_deps() {
40
cd "$srcdir"
41
42
sbcl_args=''
43
44
if [ -r "quicklisp/setup.lisp" ]; then
45
sbcl_args="$sbcl_args --load quicklisp/setup.lisp"
46
else
47
sbcl_args="$sbcl_args --load quicklisp.lisp"
48
sbcl_args="$sbcl_args --eval \
49
'(quicklisp-quickstart:install :path \"quicklisp\")'"
50
fi
51
52
while read -r dep; do
53
sbcl_args="$sbcl_args --eval '(ql:quickload \"$dep\")'"
54
done < "$_pkgname/lisp-dependencies"
55
56
sbcl_args="$sbcl_args --eval '(sb-ext:quit)'"
57
eval "sbcl --no-userinit $sbcl_args"
58
59
ln -sft quicklisp/local-projects "$srcdir/croatoan"
60
61
printf '(load "%s/quicklisp/setup.lisp")' "$srcdir" > sbclrc
62
}
63
64
build() {
65
_install_lisp_deps
66
67
cd "$srcdir/$_pkgname"
68
autoreconf -fiv
69
./configure --prefix='/usr' --sysconfdir='/etc'
70
71
72
sed -i "s%LISP_COMPILER = .*%LISP_COMPILER = sbcl \
73
--userinit '$srcdir/sbclrc'%" Makefile
74
make
75
}
76
77
package() {
78
cd "$srcdir/$_pkgname"
79
make DESTDIR="$pkgdir/" install
80
install -Dm644 LICENSES.org -t "$pkgdir/usr/share/licenses/$_pkgname"
81
}
82
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |