tuf-manager
maintainer Cromer
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a tarball from the project's own Git host, which is plausibly the maintainer's official infrastructure; building from such a source is normal for AUR packages and poses low risk despite the non-whitelisted domain.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's own Git host, which is plausibly the maintainer's official infrastructure; building from such a source is normal for AUR packages and poses low risk despite the non-whitelisted domain.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("https://git.cromer.cl/cromer/${pkgname}/archive/${pkgver}.tar.gz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Chris Cromer <chris@cromer.cl>
2
3
pkgname=tuf-manager
4
pkgver=1.2.3
5
pkgrel=1
6
pkgdesc="Program to control ASUS TUF laptop keyboard lighting and fan modes"
7
arch=("x86_64")
8
url="https://git.cromer.cl/cromer/tuf-manager"
9
license=("BSD3")
10
depends=("gtk3>=3.14" "glib2" "dbus-glib" "libnotify" "libappindicator-gtk3" "polkit" "faustus-rublag-dkms-git")
11
makedepends=("meson" "ninja" "vala")
12
source=("https://git.cromer.cl/cromer/${pkgname}/archive/${pkgver}.tar.gz")
13
sha512sums=('525bc9fd7768b0de15ae643bf325a745da969506d59c52865ccbbaee30c21bfa385c5ce2fd614c502b25708f20dc8ddfea960a17179280e99d93c5de5ad2bc95')
14
15
prepare() {
16
[ -d "${srcdir}"/build ] && rm -rf build
17
mkdir "${srcdir}"/build
18
}
19
20
build() {
21
cd "${srcdir}"/build
22
meson "${srcdir}/${pkgname}" \
23
--prefix=/usr \
24
--libexecdir=/usr/lib
25
ninja
26
}
27
28
package() {
29
cd "${srcdir}"/build
30
DESTDIR="${pkgdir}" ninja install
31
rm "${pkgdir}"/usr/share/glib-2.0/schemas/gschemas.compiled
32
}
33
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |