windows-gaming-git
maintainer main0
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The non-standard host is fedorapeople.org, which is a legitimate Fedora community hosting site; the downloaded virtio-win_amd64.vfd is a standard, well-known virtual floppy disk for Windows paravirtualized drivers, not an executable payload, and is used as data for the package; the source is checksummed (md5sum provided), reducing supply-chain risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host is fedorapeople.org, which is a legitimate Fedora community hosting site; the downloaded virtio-win_amd64.vfd is a standard, well-known virtual floppy disk for Windows paravirtualized drivers, not an executable payload, and is used as data for the package; the source is checksummed (md5sum provided), reducing supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
source=('git+https://github.com/Ediacarium/windows-gaming.git' 'https://fedorapeople.org/groups/virt/virtio-win/direct-downloads/archive-virtio/virtio-win-0.1.171-1/virtio-win_amd64.vfd')
PKGBUILD
1 offending line(s) highlighted
1
pkgname=windows-gaming-git
2
pkgver=r304.9251360
3
pkgrel=1
4
pkgdesc="Windows gaming utils"
5
arch=('x86_64')
6
url=""
7
license=('GPL')
8
groups=()
9
depends=('qemu-headless' 'sudo' 'libsystemd' 'acl' 'udev' 'coreutils' 'hwids' 'libinput' 'libxcb')
10
optdepends=('samba: shared folder' 'qemu: windowed setup')
11
makedepends=('git' 'rpmextract' 'curl' 'libarchive' 'cargo' 'mono' 'cdrkit')
12
provides=("${pkgname%-git}")
13
conflicts=("${pkgname%-git}")
14
replaces=()
15
backup=()
16
options=()
17
install="windows-gaming.install"
18
source=('git+https://github.com/Ediacarium/windows-gaming.git' 'https://fedorapeople.org/groups/virt/virtio-win/direct-downloads/archive-virtio/virtio-win-0.1.171-1/virtio-win_amd64.vfd')
19
noextract=()
20
md5sums=('SKIP' 'e8163b1e97ff85735e63218175cc0fe7')
21
22
23
pkgver() {
24
cd "$srcdir/${pkgname%-git}"
25
26
# Git, tags available
27
# printf "%s" "$(git describe --long | sed 's/\([^-]*-\)g/r\1/;s/-/./g')"
28
29
# Git, no tags available
30
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
31
}
32
33
prepare() {
34
cd "$srcdir/${pkgname%-git}"
35
sed -i 's/$(DESTDIR)\/lib/$(DESTDIR)\/usr\/lib/' Makefile
36
}
37
38
build() {
39
cd "$srcdir/${pkgname%-git}"
40
make
41
}
42
43
package() {
44
cd "$srcdir/${pkgname%-git}"
45
make DESTDIR="$pkgdir/" install
46
}
47
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |