wmdrawer
maintainer bidulock
· 4 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a standard tarball from a personal but plausible project host, building the project's own unexecuted source code, with a valid checksum; the non-whitelisted host is not inherently dangerous for a source archive.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a standard tarball from a personal but plausible project host, building the project's own unexecuted source code, with a valid checksum; the non-whitelisted host is not inherently dangerous for a source archive.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=(http://people.easter-eggs.org/~valos/wmdrawer/$pkgname-$pkgver.tar.gz)
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Brian Bidulock <bidulock@openss7.org>
2
# Contributor: Danto <danto@lavabit.com>
3
# Contributor: Mario Blättermann <mariobl@gnome.org>
4
pkgname=wmdrawer
5
pkgver=0.10.5
6
pkgrel=4
7
pkgdesc="Dockapp with retractable button bar to launch applications"
8
arch=('i686' 'x86_64')
9
url="http://people.easter-eggs.org/~valos/wmdrawer/"
10
license=('GPL')
11
groups=(x11)
12
depends=('libxt' 'gdk-pixbuf')
13
source=(http://people.easter-eggs.org/~valos/wmdrawer/$pkgname-$pkgver.tar.gz)
14
md5sums=(608bf2f75fdd084f8e63764c31a2a9a5)
15
16
prepare() {
17
cd $pkgname-$pkgver
18
19
# sed -r -i 's,CFLAGS = -O3 -Wall (.*),CFLAGS += \1,;s,LDFLAGS = ,LDFLAGS += ,' Makefile
20
sed -r -i 's,CFLAGS = -O3 -Wall (.*),CFLAGS += \1,' Makefile
21
}
22
23
build() {
24
cd $pkgname-$pkgver
25
26
make clean
27
make INCLUDES=-I/usr/include/X11
28
}
29
30
package() {
31
cd $pkgname-$pkgver
32
33
mkdir -p $pkgdir/usr/bin/
34
mkdir -p $pkgdir/usr/share/doc/$pkgname/
35
mkdir -p $pkgdir/usr/share/man/man1/
36
/usr/bin/install -c $pkgname $pkgdir/usr/bin/wmdrawer-bin
37
/usr/bin/install -c ./doc/$pkgname.1x.gz $pkgdir/usr/share/man/man1/
38
/usr/bin/install -c AUTHORS README TODO wmdrawerrc.example $pkgdir/usr/share/doc/$pkgname
39
40
#startup script
41
cat > $pkgdir/usr/bin/wmdrawer << EOF
42
#!/bin/bash
43
#test if file already exists
44
#if yes, then launch
45
46
if (test -e \$HOME/.wmdrawerrc) then
47
exec wmdrawer-bin
48
49
#if no, get /usr/share/doc/wmdrawer/wmdrawerrc.example and copy to \$HOME
50
else
51
cp /usr/share/doc/wmdrawer/wmdrawerrc.example \$HOME/.wmdrawerrc
52
exec wmdrawer-bin
53
fi
54
EOF
55
56
chmod +x $pkgdir/usr/bin/wmdrawer
57
}
58
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |