wmnetload
maintainer bidulock
· 9 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The non-standard host (tnemeth.free.fr) hosts patch files, not executables, and the main source is from GitHub; worst case is patch tampering, but the patches are checksummed and the base code is from a legitimate project source.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host (tnemeth.free.fr) hosts patch files, not executables, and the main source is from GitHub; worst case is patch tampering, but the patches are checksummed and the base code is from a legitimate project source.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
"http://tnemeth.free.fr/projets/programmes/wmnetload-1.3-tn1.patch"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: David Couzelis <drcouzelis@gmail.com>
2
pkgname=wmnetload
3
pkgver=1.3
4
pkgrel=3
5
pkgdesc="Dockapp which displays network activity in different LCD styles"
6
arch=(i686 x86_64)
7
url="http://dockapps.windowmaker.org/file.php/id/78"
8
license=('GPL')
9
depends=('libdockapp')
10
source=("https://github.com/bbidulock/wmnetload/releases/download/$pkgver/$pkgname-$pkgver.tar.gz"
11
"http://tnemeth.free.fr/projets/programmes/wmnetload-1.3-tn1.patch"
12
"http://tnemeth.free.fr/projets/programmes/wmnetload-1.3-tn2.patch")
13
md5sums=('104f594c8b30d3a0895c03679e759997'
14
'1ba977d044d035d9ae088f72380af1e0'
15
'9703e76da9777cb60d3358e5761f0841')
16
17
prepare() {
18
cd "$srcdir/$pkgname-$pkgver"
19
patch -p1 -i "$srcdir/$pkgname-$pkgver-tn1.patch"
20
patch -p1 -i "$srcdir/$pkgname-$pkgver-tn2.patch"
21
}
22
23
build() {
24
cd "$srcdir/$pkgname-$pkgver"
25
./configure --prefix=/usr
26
make LDFLAGS= RPATH=
27
}
28
29
check() {
30
cd "$srcdir/$pkgname-$pkgver"
31
make -k check
32
}
33
34
package() {
35
cd "$srcdir/$pkgname-$pkgver"
36
make DESTDIR="$pkgdir/" install
37
}
38
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |