windows-gaming-git
The non-standard host is fedorapeople.org, which is a legitimate Fedora community hosting site; the downloaded virtio-win_amd64.vfd is a standard, well-known virtual floppy disk for Windows paravirtualized drivers, not an executable payload, and is used as data for the package; the source is checksummed (md5sum provided), reducing supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host is fedorapeople.org, which is a legitimate Fedora community hosting site; the downloaded virtio-win_amd64.vfd is a standard, well-known virtual floppy disk for Windows paravirtualized drivers, not an executable payload, and is used as data for the package; the source is checksummed (md5sum provided), reducing supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
source=('git+https://github.com/Ediacarium/windows-gaming.git' 'https://fedorapeople.org/groups/virt/virtio-win/direct-downloads/archive-virtio/virtio-win-0.1.171-1/virtio-win_amd64.vfd')
PKGBUILD
1 offending line(s) highlightedpkgname=windows-gaming-git
pkgver=r304.9251360
pkgrel=1
pkgdesc="Windows gaming utils"
arch=('x86_64')
url=""
license=('GPL')
groups=()
depends=('qemu-headless' 'sudo' 'libsystemd' 'acl' 'udev' 'coreutils' 'hwids' 'libinput' 'libxcb')
optdepends=('samba: shared folder' 'qemu: windowed setup')
makedepends=('git' 'rpmextract' 'curl' 'libarchive' 'cargo' 'mono' 'cdrkit')
provides=("${pkgname%-git}")
conflicts=("${pkgname%-git}")
replaces=()
backup=()
options=()
install="windows-gaming.install"
source=('git+https://github.com/Ediacarium/windows-gaming.git' 'https://fedorapeople.org/groups/virt/virtio-win/direct-downloads/archive-virtio/virtio-win-0.1.171-1/virtio-win_amd64.vfd')
noextract=()
md5sums=('SKIP' 'e8163b1e97ff85735e63218175cc0fe7')
pkgver() {
cd "$srcdir/${pkgname%-git}"
# Git, tags available
# printf "%s" "$(git describe --long | sed 's/\([^-]*-\)g/r\1/;s/-/./g')"
# Git, no tags available
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
}
prepare() {
cd "$srcdir/${pkgname%-git}"
sed -i 's/$(DESTDIR)\/lib/$(DESTDIR)\/usr\/lib/' Makefile
}
build() {
cd "$srcdir/${pkgname%-git}"
make
}
package() {
cd "$srcdir/${pkgname%-git}"
make DESTDIR="$pkgdir/" install
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |