virt-viewer-light
The source is a patch from a GitLab commit URL on a non-whitelisted host, but it is applied to the official virt-viewer source and does not execute remote code; the patch is publicly viewable and the main tarball is verified via b2sum.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a patch from a GitLab commit URL on a non-whitelisted host, but it is applied to the official virt-viewer source and does not execute remote code; the patch is publicly viewable and the main tarball is verified via b2sum.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=("https://virt-manager.org/download/sources/virt-viewer/virt-viewer-${pkgver}.tar.xz"{,.asc}
PKGBUILD
1 offending line(s) highlighted# Maintainer: s3rj1k <evasive dot gyron at gmail dot com>
# Do not forget to run `makepkg --printsrcinfo > .SRCINFO`
_pkgname=virt-viewer
pkgname=$_pkgname-light
pkgver=11.0
pkgrel=3
pkgdesc='A lightweight interface for interacting with the graphical display of virtualized guest OS. This package contains a patch drop the header bar.'
arch=('x86_64')
url='https://gitlab.com/virt-viewer/virt-viewer'
license=('GPL')
depends=('gtk-vnc' 'libvirt' 'libvirt-glib')
makedepends=('meson' 'intltool' 'gobject-introspection')
replaces=("${_pkgname}")
provides=("${_pkgname}")
conflicts=("${_pkgname}")
source=("https://virt-manager.org/download/sources/virt-viewer/virt-viewer-${pkgver}.tar.xz"{,.asc}
"https://gitlab.com/Paper_/virt-viewer/-/commit/41cc016278e713d3db156761fce6437dff81a53a.patch")
b2sums=('41914a60361f0a47a0b0b54962d228ffaec67c6b69c664bb6fe683b7074dd5e2136d2bf3528b6e1b6b785cc4e337125fe16fdd94dd603dd42e8fde543931241a'
'SKIP'
'd1b79f2bdc2749049767d7e22cf530c04438547fb3485fd0ab084222600ddcb08b8a27e104216c5da9b25d9c792d1cdf085d1c23c988194c3c6c22cf05eaa0e2')
validpgpkeys=('DAF3A6FDB26B62912D0E8E3FBE86EBB415104FDF') # Daniel P. Berrange
prepare() {
cd "${_pkgname}-${pkgver}"
patch -p1 < "${srcdir}/41cc016278e713d3db156761fce6437dff81a53a.patch"
}
build() {
arch-meson "${_pkgname}-${pkgver}" build \
-Dbash_completion=disabled \
-Dlibvirt=enabled \
-Dovirt=disabled \
-Dspice=disabled \
-Dvnc=enabled \
-Dvte=disabled
ninja -C build
}
package() {
DESTDIR="${pkgdir}" ninja -C build install
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |