winegui-bin

LOW
maintainer JoseskVolpe 5 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a prebuilt tarball from the project maintainer's domain, used to install a GUI for Wine; while the host is not a standard forge, it is plausibly official and the package does not execute untrusted code beyond normal software installation.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt tarball from the project maintainer's domain, used to install a GUI for Wine; while the host is not a standard forge, it is plausibly official and the package does not execute untrusted code beyond normal software installation.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:24 source=("$pkgname-$pkgver.tar.gz::https://winegui.melroy.org/downloads/WineGUI-v$pkgver.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Josesk Volpe <joseskvolpe at gmail dot com>
2# Co-Maintainer: Melroy van den Berg <melroy at melroy dot org>
3pkgname=winegui-bin
4pkgver=4.4.0
5pkgrel=1
6pkgdesc="A user-friendly WINE graphical interface"
7arch=('x86_64')
8url="https://gitlab.melroy.org/melroy/winegui"
9license=('AGPL3')
10depends=(
11 'gtkmm-4.0'
12 'cabextract' # used by winetricks
13 'unzip'
14 'p7zip'
15 'wget' # to download winetricks/Wine runner latest release
16 'wine'
17 'zenity' # used by winetricks
18 'tar' # used to untar Wine runenr downloads
19 'xz' # used to untar/xz/lzma Wine runner downloads
20 'python' # used for UMU launcher (when using GE-Proton)
21)
22conflicts=('winegui')
23provides=('winegui')
24source=("$pkgname-$pkgver.tar.gz::https://winegui.melroy.org/downloads/WineGUI-v$pkgver.tar.gz")
25md5sums=('5a02780bbfcfcfc6cc39ab06b6eab6d8')
26
27package() {
28 mkdir $pkgdir/usr
29 mv WineGUI-v$pkgver/* "$pkgdir/usr/"
30}
31

Changes since previous scan

--- PKGBUILD @ 2026-09-13 00:19
+++ PKGBUILD @ 2026-09-17 00:27
@@ -1,7 +1,7 @@
# Maintainer: Josesk Volpe <joseskvolpe at gmail dot com>
# Co-Maintainer: Melroy van den Berg <melroy at melroy dot org>
pkgname=winegui-bin
-pkgver=4.2.1
+pkgver=4.4.0
pkgrel=1
pkgdesc="A user-friendly WINE graphical interface"
arch=('x86_64')
@@ -17,11 +17,12 @@
'zenity' # used by winetricks
'tar' # used to untar Wine runenr downloads
'xz' # used to untar/xz/lzma Wine runner downloads
+ 'python' # used for UMU launcher (when using GE-Proton)
)
conflicts=('winegui')
provides=('winegui')
source=("$pkgname-$pkgver.tar.gz::https://winegui.melroy.org/downloads/WineGUI-v$pkgver.tar.gz")
-md5sums=('876b8dfdf5cd53844900df917d276646')
+md5sums=('5a02780bbfcfcfc6cc39ab06b6eab6d8')
package() {
mkdir $pkgdir/usr

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 13:14:45 Medium 1
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion