wgsim

LOW
maintainer imjiaoyuan 0 votes scanned 2026-10-08 16:09:18.783063
View on AUR
Why flagged

The package builds from a pinned commit of a well-known tool hosted on GitHub; the source is verifiable and the build process is transparent, with no remote code execution or untrusted binaries.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package builds from a pinned commit of a well-known tool hosted on GitHub; the source is verifiable and the build process is transparent, with no remote code execution or untrusted binaries.

PKGBUILD

1# Maintainer: imjiaoyuan <imjiaoyuan@gmail.com>
2# Upstream publishes no tags and no releases and has not changed since 2011
3# (wgsim.c still reports 0.3.1-r13), so pkgver is the pinned commit's date and
4# _tag carries the commit itself.
5
6pkgname=wgsim
7_tag=a12da3375ff3b51a5594d4b6fa35591173ecc229
8pkgver=20111017
9pkgrel=1
10pkgdesc="Small tool for simulating sequence reads from a reference genome"
11arch=('x86_64')
12url="https://github.com/lh3/wgsim"
13license=('MIT')
14depends=('glibc' 'perl' 'zlib')
15source=("$pkgname-$pkgver.tar.gz::${url}/archive/${_tag}.tar.gz")
16sha256sums=('e1e6bff5c084e4494023505206ae3e0b0f5a315c9f7390b2f347c370c7f36533')
17
18build() {
19 cd "$srcdir/$pkgname-$_tag"
20 cc $CPPFLAGS $CFLAGS -Wall -o wgsim wgsim.c -lz -lm $LDFLAGS
21}
22
23package() {
24 cd "$srcdir/$pkgname-$_tag"
25 install -Dm755 wgsim "$pkgdir/usr/bin/wgsim"
26 install -Dm755 wgsim_eval.pl "$pkgdir/usr/bin/wgsim_eval.pl"
27 # upstream ships no LICENSE file: the MIT grant is the header of wgsim.c
28 install -d "$pkgdir/usr/share/licenses/$pkgname"
29 awk 'NR==1,/^\*\//' wgsim.c > "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
30}
31

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 16:09:18 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion