vgs-git

LOW
maintainer vanillagreen 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

Package builds from a legitimate project Git repository, uses a dynamic pkgver from the project's own tooling, and has no remote code execution or unverifiable binaries; the low severity is due to few votes and recent upload, not malicious content.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): Package builds from a legitimate project Git repository, uses a dynamic pkgver from the project's own tooling, and has no remote code execution or unverifiable binaries; the low severity is due to few votes and recent upload, not malicious content.

PKGBUILD

1# Maintainer: VanillaGreen <brad@vanillagreen.com>
2#
3# The development package, built from main. docs/architecture/distribution-arch.md
4# states the rules scripts/check-packaging.js enforces on
5# this file and on ../vgs/PKGBUILD. makepkg rewrites pkgver from pkgver().
6
7pkgname=vgs-git
8pkgver=0.1.0
9pkgrel=1
10pkgdesc='Desktop shell for Hyprland, built on Quickshell (development version)'
11arch=('any')
12url='https://github.com/vanillagreencom/vgs'
13license=('MIT AND OFL-1.1 AND ISC AND Apache-2.0')
14depends=(
15 'quickshell>=0.3.1'
16 'hyprland>=0.56'
17 'bash'
18 'coreutils'
19 'util-linux'
20 'nodejs>=18'
21 'python'
22 'libxkbcommon'
23 'xkeyboard-config'
24 'git'
25 'gum'
26 'xdg-terminal-exec'
27)
28optdepends=(
29 'wtype: Jarvis text and key input'
30 'wlrctl: Jarvis pointer input without an input service'
31 'ydotool: Jarvis pointer fallback with an already running input service'
32 'agent-browser-bin: private Jarvis browser driver'
33 'chromium: browser for Jarvis setup'
34 'pipewire: Jarvis half-duplex audio capture, playback and discovery'
35 'fd: launcher file and folder search'
36 'fzf: launcher file search matching and the package pickers in floating TUIs'
37 'bluez-utils: bluetoothctl, the Bluetooth pairing agent that answers pairing prompts'
38 'file: launcher open-with list for a found file'
39 'grim: launcher Screenshot'
40 'slurp: launcher Screenshot region selection'
41 'wl-clipboard: launcher Screenshot and Copy path, and the Jarvis clipboard tools'
42 'libnotify: notify-send, to post notifications to the VGS notification server and from Jarvis'
43 'playerctl: Jarvis media play, pause and next'
44 'wireplumber: wpctl, for Jarvis speaker volume and mute'
45 'xdg-utils: launcher Files'
46 'pacman-contrib: checkupdates, for the package update check'
47 'snapper: a snapshot before the update pipeline changes packages'
48 'timeshift: a snapshot before the update pipeline changes packages, without snapper'
49 'less: the last update log in the Updates flyout'
50 'sudo: package installs and the browser policy writer in floating TUIs'
51 'imagemagick: square Slack profile photos and custom emoji in notifications'
52 'curl: Slack profile photos, custom emoji and Web API calls in notifications'
53 'libsecret: secret-tool, for Slack tokens and Jarvis provider keys in the keyring'
54 'bubblewrap: kernel confinement for Jarvis shell commands'
55 'uv: installs the locked Jarvis local voice runtime'
56 'glib2: gio, opens files and web links for Jarvis'
57 'nvidia-utils: verifies a selected Jarvis CUDA local voice tier'
58 'vsys: the agent dashboard and warden the Agent Warden plugin reads'
59 'mise: Dev Tools installs, updates and removes developer tools'
60 'cronie: crontab, which schedules automations where no systemd user manager answers'
61 'systemd: before-suspend locking and Jarvis key presence without reading secrets'
62 'iproute2: ss, for Jarvis local model-server discovery without inference'
63 'tmux: several Jarvis coding tasks at once'
64 'dbus: dbus-monitor, so the lock screen hears logind announce a suspend'
65)
66makedepends=('git')
67provides=("vgs=$pkgver")
68conflicts=('vgs' 'vgs-shell' 'vgs-shell-git')
69source=("vgs::git+$url.git")
70sha256sums=('SKIP')
71
72# The tree's own version judge names the version, so the package and
73# `vgsh --version` in the checkout print the same X.Y.Z.r<N>.g<hash>.
74pkgver() {
75 local out
76 cd "$srcdir/vgs"
77 out="$(./bin/vgsh version)" || return 1
78 out="${out#vgs }"
79 if [[ ! $out =~ ^[0-9]+\.[0-9]+\.[0-9]+\.r[0-9]+\.g[0-9a-f]+$ ]]; then
80 printf 'vgs-git: refused: pkgver=%s\n' "$out" >&2
81 return 1
82 fi
83 printf '%s\n' "$out"
84}
85
86package() {
87 cd "$srcdir/vgs"
88 DESTDIR="$pkgdir" PREFIX=/usr ./packaging/install-system.sh
89}
90

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion