volta-reader
maintainer book-enjoyer
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package builds from source hosted on a non-whitelisted but plausibly project-owned Git server; the source is verified with a fixed checksum, and no remote code execution or untrusted binaries are involved.
Triggered rules
LOW
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds from source hosted on a non-whitelisted but plausibly project-owned Git server; the source is verified with a fixed checksum, and no remote code execution or untrusted binaries are involved.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("$pkgname-$pkgver.tar.gz::https://git.komun.buzz/Book-Enjoyer/volta/archive/v$pkgver.tar.gz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Book-Enjoyer <catperson@catperson.online>
2
pkgname=volta-reader
3
pkgver=0.1.2
4
pkgrel=1
5
pkgdesc="Desktop ebook reader with RSVP speed reading — dual-mode TUI + LÖVE GUI"
6
arch=('x86_64')
7
url="https://git.komun.buzz/Book-Enjoyer/volta"
8
license=('MIT')
9
depends=('love' 'poppler' 'zenity' 'curl' 'gcc-libs')
10
makedepends=('cargo' 'rust')
11
conflicts=('volta')
12
source=("$pkgname-$pkgver.tar.gz::https://git.komun.buzz/Book-Enjoyer/volta/archive/v$pkgver.tar.gz")
13
sha256sums=('51675ea3753c01184039833d3617d698f734180b756d482ea3750d925966830e')
14
15
build() {
16
cd "$srcdir/volta"
17
cargo build --release --manifest-path core/Cargo.toml
18
}
19
20
check() {
21
cd "$srcdir/volta"
22
cargo test --release --manifest-path core/Cargo.toml
23
}
24
25
package() {
26
cd "$srcdir/volta"
27
28
# TUI binary
29
install -Dm755 target/release/volta-tui "$pkgdir/usr/bin/volta-tui"
30
31
# Shared library for LÖVE
32
install -Dm755 target/release/libvolta_core.so "$pkgdir/usr/lib/volta/libvolta_core.so"
33
34
# LÖVE frontend
35
install -dm755 "$pkgdir/usr/share/volta/frontend"
36
cp -r frontend/* "$pkgdir/usr/share/volta/frontend/"
37
38
# Launcher script
39
install -Dm755 volta "$pkgdir/usr/bin/volta"
40
41
# Desktop entry (with system path)
42
sed 's|Exec=.*|Exec=/usr/bin/volta|' volta.desktop > "$srcdir/volta.desktop.system"
43
install -Dm644 "$srcdir/volta.desktop.system" "$pkgdir/usr/share/applications/volta.desktop"
44
45
# Docs
46
install -Dm644 README.md "$pkgdir/usr/share/doc/volta/README.md"
47
install -Dm644 KEYBINDINGS.md "$pkgdir/usr/share/doc/volta/KEYBINDINGS.md"
48
49
# License
50
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/volta/LICENSE"
51
}
52
Changes since previous scan
--- PKGBUILD @ 2026-07-29 09:11+++ PKGBUILD @ 2026-08-03 00:08@@ -1,6 +1,6 @@ # Maintainer: Book-Enjoyer <catperson@catperson.online> pkgname=volta-reader-pkgver=0.1.1+pkgver=0.1.2 pkgrel=1 pkgdesc="Desktop ebook reader with RSVP speed reading — dual-mode TUI + LÖVE GUI" arch=('x86_64')@@ -10,20 +10,20 @@ makedepends=('cargo' 'rust') conflicts=('volta') source=("$pkgname-$pkgver.tar.gz::https://git.komun.buzz/Book-Enjoyer/volta/archive/v$pkgver.tar.gz")-sha256sums=('ea39bcc9391494642bdbdcc0ca7170867500b3beddb0425544d518649f7573b3')+sha256sums=('51675ea3753c01184039833d3617d698f734180b756d482ea3750d925966830e') build() {- cd "$srcdir/$pkgname-$pkgver"+ cd "$srcdir/volta" cargo build --release --manifest-path core/Cargo.toml } check() {- cd "$srcdir/$pkgname-$pkgver"+ cd "$srcdir/volta" cargo test --release --manifest-path core/Cargo.toml } package() {- cd "$srcdir/$pkgname-$pkgver"+ cd "$srcdir/volta" # TUI binary install -Dm755 target/release/volta-tui "$pkgdir/usr/bin/volta-tui"Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 3 |
| 2026-08-02 00:16:08 | LOW | 3 |
| 2026-08-01 00:11:18 | LOW | 3 |
| 2026-07-31 00:14:10 | LOW | 3 |
| 2026-07-30 00:17:23 | LOW | 3 |
| 2026-07-29 11:11:22 | MEDIUM | 2 |
| 2026-07-29 09:11:06 | MEDIUM | 2 |
| 2026-07-29 07:10:52 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | LOW | 3 |
| 2026-07-28 00:07:28 | LOW | 3 |
| 2026-07-27 00:24:32 | LOW | 3 |
| 2026-07-26 00:07:32 | LOW | 3 |
| 2026-07-25 05:31:37 | LOW | 3 |
| 2026-07-25 05:29:17 | MEDIUM | 2 |