visurf-git
The package downloads the official Netsurf source tarball from a non-whitelisted but project-associated host (download.netsurf-browser.org), which is a standard release location; combined with a git checkout of the actual visurf frontend, this constitutes a normal source build with no remote code execution or malicious payload, so the risk is low despite the non-standard host.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads the official Netsurf source tarball from a non-whitelisted but project-associated host (download.netsurf-browser.org), which is a standard release location; combined with a git checkout of the actual visurf frontend, this constitutes a normal source build with no remote code execution or malicious payload, so the risk is low despite the non-standard host.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
'http://download.netsurf-browser.org/netsurf/releases/source-full/netsurf-all-3.10.tar.gz' -
PKGBUILD:18
'libcss::git+git://git.netsurf-browser.org/libcss.git#commit=f420dd16136de1dc07f18824c6d0f5540d5df6d1'
PKGBUILD
2 offending line(s) highlighted# Maintainer: Rene Hickersberger <r@renehsz.com>
pkgname='visurf-git'
pkgver=3.10.r356.g8f7036e44
pkgrel=1
pkgdesc='Minimalistic frontend for Netsurf with vi-like keybindings (Wayland only)'
url='https://sr.ht/~sircmpwn/visurf/'
license=('GPL2' 'MIT')
depends=('curl' 'libjpeg-turbo' 'libpng' 'zlib' 'openssl' 'expat' 'wayland' 'wayland-protocols' 'cairo' 'pango' 'libxkbcommon')
makedepends=('git' 'gperf' 'perl-html-parser' 'flex' 'bison')
provides=('visurf')
conflicts=('visurf' 'netsurf')
arch=('x86_64')
source=(
'http://download.netsurf-browser.org/netsurf/releases/source-full/netsurf-all-3.10.tar.gz'
"visurf::git+https://git.sr.ht/~sircmpwn/visurf"
'libcss::git+git://git.netsurf-browser.org/libcss.git#commit=f420dd16136de1dc07f18824c6d0f5540d5df6d1'
)
sha256sums=(
'495adf6b6614ce36fca6c605f7c321f9cb4a3df838043158122678ce2b3325b7'
'SKIP'
'SKIP'
)
pkgver() {
cd "$srcdir/visurf"
git describe --always | sed -e 's:release/::; s:-\([0-9]\+\)-:.r\1.:'
}
prepare() {
cd "$srcdir/visurf"
[ -e "$srcdir/netsurf-all-3.10"/netsurf ] && rm -r "$srcdir/netsurf-all-3.10"/netsurf
[ -e "$srcdir/netsurf-all-3.10"/libcss ] && rm -r "$srcdir/netsurf-all-3.10"/libcss
cp -r "$srcdir/visurf" "$srcdir/netsurf-all-3.10/netsurf"
cp -r "$srcdir/libcss" "$srcdir/netsurf-all-3.10/libcss"
}
build() {
cd "$srcdir/netsurf-all-3.10"
export CFLAGS=-w
make TARGET=visurf PREFIX=/usr LIBDIR=lib INCLUDEDIR=include -j$(nproc)
}
package() {
cd "$srcdir/netsurf-all-3.10"
make TARGET=visurf PREFIX=/usr LIBDIR=lib INCLUDEDIR=include DESTDIR="$pkgdir" install
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |