wuffs-fuzzers-git
wuffs-git
scanned 2026-10-02 00:00:32.890515
The package builds from the official GitHub source of a legitimate project and uses 'go get' to fetch build tools from the same trusted domain; the non-standard host is due to variable use but resolves to github.com, posing no real risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds from the official GitHub source of a legitimate project and uses 'go get' to fetch build tools from the same trusted domain; the non-standard host is due to variable use but resolves to github.com, posing no real risk.
2 higher static findings superseded - not the current verdict (shown for transparency)
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:120
go install -v -modcacherw github.com/google/wuffs/cmd/...
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:56
"${_gitname}::git+https://${_githost}/${_gituser}/${_gitname}.git"
PKGBUILD
2 offending line(s) highlighted# Maintainer: dreieck (https://aur.archlinux.org/account/dreieck)
_gitname="wuffs"
_pkgbase="${_gitname}"
pkgbase="${_pkgbase}-git"
pkgname=(
"${_pkgbase}-lib-git"
"${_pkgbase}-examples-git"
"${_pkgbase}-fuzzers-git"
"${_pkgbase}-lang-git"
"${_pkgbase}-docs-git"
"${_pkgbase}-license-git"
)
pkgdesc="A memory-safe programming language, and a standard library, for Wrangling Untrusted File Formats Safely. Wrangling includes parsing, decoding and encoding. Example file formats include images, audio, video, fonts and compressed archives."
pkgver=0.3.5+47.r4035.20260916.f31d952b
pkgrel=1
arch=(
'i686'
'x86_64'
'armv6h'
'armv7h'
'aarch64'
'pentium4'
'riscv64'
)
_githost='github.com'
_gituser='google'
url="https://${_githost}/${_gituser}/${_gitname}"
license=(
"MIT"
"Apache-2.0"
)
makedepends=(
'gcc' # Yes, it needs both clang and GCC!
'gcc-libs'
'glibc'
'git'
'go'
"libxcb"
"lz4"
"sdl2"
"sdl2_image"
"xcb-util-image"
"xcb-util-renderutil"
"zlib"
"zstd"
)
checkdepends=()
source=(
"${_gitname}::git+https://${_githost}/${_gituser}/${_gitname}.git"
# "wuffs-build-all_disable-tests.patch" # Not needed if we don't run build-all.sh.
"wuffs-test-all.sh"
)
sha256sums=(
'SKIP' # Main upstream source.
# '85cbe5911efa30fde54fc364aecf8f2d1e89f0cb387654127d020037caef447c' # wuffs-build-all_disable-tests.patch
'2cd9df1708364eb3db73c56beb5bd0400adef6d670033195c4647378ec612d29' # wuffs-test-all.sh
)
prepare() {
export GOPATH="${srcdir}/.go"
export GOBIN="${GOPATH}/bin"
cd "${srcdir}/${_gitname}"
# for _patch in "${srcdir}"/wuffs-build-all_disable-tests.patch; do # Not needed if we don't run build-all.sh.
# printf '%s\n' " -> Applying patch '$(basename "${_patch}")' ..."
# patch -Np1 --follow-symlinks -i "${_patch}"
# done
printf '%s\n' " --> running 'go get -v -modcacherw github.com/google/wuffs/cmd/...' ..."
go get -v -modcacherw github.com/google/wuffs/cmd/...
printf '\n'
git log > "${srcdir}/git.log"
}
pkgver() {
cd "${srcdir}/${_gitname}"
_ver="$(git describe --tags | sed -E -e 's|^spin-in-||' -e 's|^[vV]||' -e 's|\-g[0-9a-f]*$||' | tr '-' '+')"
_rev="$(git rev-list --count HEAD)"
_date="$(git log -1 --date=format:"%Y%m%d" --format="%ad")"
_hash="$(git rev-parse --short HEAD)"
if [ -z "${_ver}" ]; then
error "Version could not be determined."
return 1
else
printf '%s' "${_ver}.r${_rev}.${_date}.${_hash}"
fi
}
build() {
export GOPATH="${srcdir}/.go"
export GOBIN="${GOPATH}/bin"
export PATH="${GOBIN}:${PATH}"
local _CFLAGSADDITIONS=""
local _SILENCEWARNINGS=("stringop-overflow")
local _warning
for _warning in "${_SILENCEWARNINGS[@]}"; do
_CFLAGSADDITIONS+=" -Wno-${_warning} -Wno-error=${_warning}"
done
CFLAGS+="${_CFLAGSADDITIONS}"
CXXFLAGS+="${_CFLAGSADDITIONS}"
export CFLAGS
export CXXFLAGS
cd "${srcdir}/${_gitname}"
# Excerpts from build-all.sh:
printf '%s\n' " --> running 'go install -v -modcacherw github.com/google/wuffs/cmd/...' ..."
go install -v -modcacherw github.com/google/wuffs/cmd/...
printf '\n'
printf '%s\n' " --> running 'wuffs gen -langs 'c'' ..."
wuffs gen -langs 'c'
printf '\n'
printf '%s\n' " --> running 'wuffs genlib -ccompilers gcc -langs 'c' -skipgen' ..."
wuffs genlib -ccompilers gcc -langs 'c' -skipgen
printf '\n'
printf '%s\n' " --> running './build-example.sh' ..."
./build-example.sh
printf '\n'
printf '%s\n' " --> running './build-fuzz.sh' ..."
./build-fuzz.sh
printf '\n'
}
# ### 2026-08-03: `check()` Disabled, since `gen/bin/fuzz-pixel_swizzler` crashes with a segmentation fault.
# check() {
# cd "${srcdir}/${_gitname}"
#
# "${srcdir}"/wuffs-test-all.sh
# }
package_wuffs-lib-git() {
pkgdesc='A memory-safe standard library for Wrangling Untrusted File Formats Safely. Wrangling includes parsing, decoding and encoding. Example file formats include images, audio, video, fonts and compressed archives.'
depends=(
"glibc"
"wuffs-license"
)
provides=(
"wuffs-lib=${pkgver}"
"libwuffs.so"
"libwuffs.a"
)
conflicts=(
"wuffs-lib"
)
optdepends=(
"python-pywuffs: For python binding."
"wuffs-docs: For the documentation of this software."
)
cd "${srcdir}/${_gitname}"
install -Dvm644 -t "${pkgdir}/usr/include" release/c/*.c gen/c/*.c
install -Dvm755 -t "${pkgdir}/usr/lib" gen/lib/c/gcc-dynamic/libwuffs.so
install -Dvm644 -t "${pkgdir}/usr/lib" gen/lib/c/gcc-static/libwuffs.a
install -Dvm644 -t "${pkgdir}/usr/share/doc/wuffs-lib" release/c/README.md
install -dvm755 "${pkgdir}/usr/share/licenses"
ln -svr "${pkgdir}/usr/share/licenses/wuffs" "${pkgdir}/usr/share/licenses"/wuffs-lib-git
}
package_wuffs-examples-git() {
pkgdesc='Example programmes for wuffs, a memory-safe programming language and standard library for Wrangling Untrusted File Formats Safely.'
depends=(
"gcc-libs"
"glibc"
"sdl2"
"sdl2_image"
"xcb-util-image"
"xcb-util-renderutil"
"wuffs-license"
)
provides=(
"wuffs-examples=${pkgver}"
)
conflicts=(
"wuffs-examples"
)
optdepends=(
"wuffs-docs: For the documentation of this software."
)
cd "${srcdir}/${_gitname}"
local _bins _bin
_bins=`ls -1 gen/bin/example-*`
for _bin in ${_bins}; do
_name="$(basename "${_bin}" | sed -E -e 's|^example-||')"
install -Dvm755 "${_bin}" "${pkgdir}/usr/bin"/wuffs-"${_name}"
done
install -Dvm644 -t "${pkgdir}/usr/share/doc/wuffs-examples" example/README.md
install -dvm755 "${pkgdir}/usr/share/licenses"
ln -svr "${pkgdir}/usr/share/licenses/wuffs" "${pkgdir}/usr/share/licenses"/wuffs-examples-git
}
package_wuffs-fuzzers-git() {
pkgdesc='Fuzzer programmes for wuffs, a memory-safe programming language and standard library for Wrangling Untrusted File Formats Safely.'
depends=(
"gcc-libs"
"glibc"
"wuffs-license"
)
provides=(
"wuffs-fuzzers=${pkgver}"
)
conflicts=(
"wuffs-fuzzers"
)
optdepends=(
"wuffs-docs: For the documentation of this software."
)
cd "${srcdir}/${_gitname}"
local _bins _bin
_bins=`ls -1 gen/bin/fuzz-*`
for _bin in ${_bins}; do
_name="$(basename "${_bin}")"
install -Dvm755 "${_bin}" "${pkgdir}/usr/bin"/wuffs-"${_name}"
done
install -Dvm644 -t "${pkgdir}/usr/share/doc/wuffs-fuzzers" fuzz/c/std/README.md
install -dvm755 "${pkgdir}/usr/share/licenses"
ln -svr "${pkgdir}/usr/share/licenses/wuffs" "${pkgdir}/usr/share/licenses"/wuffs-fuzzers-git
}
package_wuffs-lang-git() {
pkgdesc='A memory-safe programming language for Wrangling Untrusted File Formats Safely. Wrangling includes parsing, decoding and encoding. Example file formats include images, audio, video, fonts and compressed archives.'
depends=(
"wuffs-license"
)
provides=(
"wuffs-lang=${pkgver}"
"dumbindent=${pkgver}"
"handsum=${pkgver}"
"ractool=${pkgver}"
"wuffs=${pkgver}"
"wuffs-c=${pkgver}"
"wuffsfmt=${pkgver}"
)
conflicts=(
"wuffs-lang"
"dumbindent"
"handsum"
"ractool"
"wuffs"
"wuffs-c"
"wuffsfmt"
)
optdepends=(
"glibc: For 'ractool'."
"liblz4.so: For 'ractool'."
"libz.so: For 'ractool'."
"libzstd.so: For 'ractool'."
"wuffs-docs: For the documentation of this software."
)
export GOPATH="${srcdir}/.go"
export GOBIN="${GOPATH}/bin"
cd "${srcdir}/${_gitname}"
install -Dvm755 -t "${pkgdir}/usr/bin" "${GOBIN}"/{dumbindent,handsum,ractool,wuffs,wuffs-c,wuffsfmt}
install -dvm755 "${pkgdir}/usr/share/licenses"
ln -svr "${pkgdir}/usr/share/licenses/wuffs" "${pkgdir}/usr/share/licenses"/wuffs-lang-git
}
package_wuffs-docs-git() {
pkgdesc='Documentation for "Wuffs the Library" and "Wuffs the Language", as well as the corresponding example binaries.'
depends=("wuffs-license")
provides=(
"wuffs-docs=${pkgver}"
)
conflicts=(
"wuffs-docs"
)
optdepends=(
"wuffs-lib: The library this documentation is for."
"wuffs-lang: The programming language this documentation is for."
"wuffs-examples: The example programmes this documentation is for."
"wuffs-fuzzers: The fuzzer programmes this documentation is for."
)
arch=('any')
cd "${srcdir}/${_gitname}"
install -Dvm644 -t "${pkgdir}/usr/share/doc/${_pkgbase}" "${srcdir}"/git.log AUTHORS BUILD.md CONTRIBUTING.md CONTRIBUTORS README.md
cp -rv doc "${pkgdir}/usr/share/doc/${_pkgbase}"/
install -dvm755 "${pkgdir}/usr/share/licenses"
ln -svr "${pkgdir}/usr/share/licenses/wuffs" "${pkgdir}/usr/share/licenses"/wuffs-docs-git
}
package_wuffs-license-git() {
pkgdesc='Common license for "Wuffs the Library" and "Wuffs the Language", as well as the corresponding example binaries.'
depends=()
provides=(
"wuffs-license=${pkgver}"
)
conflicts=(
"wuffs-license"
)
optdepends=(
"wuffs-lib: The library this license is for."
"wuffs-lang: The programming language this license is for."
"wuffs-examples: The example programmes this license is for."
"wuffs-fuzzers: The fuzzer programmes this license is for."
)
arch=('any')
cd "${srcdir}/${_gitname}"
cd "${srcdir}/${_gitname}"
install -Dvm644 -t "${pkgdir}/usr/share/licenses/wuffs" LICENSE LICENSE-APACHE LICENSE-MIT
ln -svr "${pkgdir}/usr/share/licenses/wuffs" "${pkgdir}/usr/share/licenses"/wuffs-license-git
ln -svr "${pkgdir}/usr/share/licenses/wuffs" "${pkgdir}/usr/share/licenses"/wuffs-license
}
Changes since previous scan
--- PKGBUILD @ 2026-09-22 00:15+++ PKGBUILD @ 2026-10-02 00:00@@ -15,7 +15,7 @@ pkgdesc="A memory-safe programming language, and a standard library, for Wrangling Untrusted File Formats Safely. Wrangling includes parsing, decoding and encoding. Example file formats include images, audio, video, fonts and compressed archives." -pkgver=0.3.5+30.r4018.20260903.0f214ba5+pkgver=0.3.5+47.r4035.20260916.f31d952b pkgrel=1 arch=(Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 3 |
| 2026-10-01 00:02:06 | Low | 3 |
| 2026-09-30 00:20:07 | Low | 3 |
| 2026-09-29 00:07:46 | Low | 3 |
| 2026-09-28 00:28:32 | Low | 3 |
| 2026-09-27 00:07:07 | Low | 3 |
| 2026-09-26 00:12:15 | Low | 3 |
| 2026-09-25 00:03:36 | Low | 3 |
| 2026-09-24 00:24:14 | Low | 3 |
| 2026-09-23 00:28:13 | Low | 3 |
| 2026-09-22 13:37:53 | Medium | 2 |
| 2026-09-22 00:15:14 | Low | 3 |
| 2026-09-21 00:26:32 | Low | 3 |
| 2026-09-20 00:25:31 | Low | 3 |
| 2026-09-19 00:25:36 | Low | 3 |
| 2026-09-18 00:17:11 | Low | 3 |
| 2026-09-17 00:27:14 | Low | 3 |
| 2026-09-16 00:03:17 | Low | 3 |
| 2026-09-15 00:25:31 | Low | 3 |
| 2026-09-14 00:27:57 | Low | 3 |