zcc

LOW
maintainer zaidejjo 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package downloads a prebuilt ZZ compiler from the same maintainer's GitHub release, which is used to build the zcc tool; while the host is not whitelisted, it is the project's official repository, and the source code is available and verifiable, reducing supply-chain risk.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads a prebuilt ZZ compiler from the same maintainer's GitHub release, which is used to build the zcc tool; while the host is not whitelisted, it is the project's official repository, and the source code is available and verifiable, reducing supply-chain risk.

PKGBUILD

1# Maintainer: zaidejjo
2# Generated by zcc's release workflow from PKGBUILD.template — do not edit
3# in the AUR repo directly; change the template and cut a new release.
4#
5# The ZZ compiler arrives PREBUILT (pinned release zip, see
6# packaging/zz.version in the zcc repo) — nothing is compiled except zcc
7# itself, so installs take seconds, not tens of minutes.
8pkgname=zcc
9pkgver=0.1.0
10pkgrel=1
11pkgdesc='Blazing-fast code counter (tokei clone) written in ZZ'
12arch=('x86_64')
13url='https://github.com/zaidejjo/zcc'
14license=('MIT')
15depends=('glibc' 'sqlite')
16makedepends=('clang' 'unzip')
17source=("zcc-$pkgver-src.tar.gz::$url/releases/download/v$pkgver/zcc-$pkgver-src.tar.gz"
18 "zz-0.1.4-$CARCH.zip::https://github.com/zaidejjo/zz/releases/download/v0.1.4/zz-0.1.4-linux-x86_64.zip")
19sha256sums=('b61716a7515ad79268efd52c15c3771b75b77df810e1b831e308dca172ffa0c2'
20 'ed9868ecbcc2325d63d751e3109cf204d73b51cd83ddfeb1a14e6fa852e82623')
21
22build() {
23 # Prebuilt toolchain (auto-extracted flat into $srcdir by makepkg).
24 export PATH="$srcdir:$PATH"
25 # Stamp the release version (source tarball carries the tag tree).
26 cd "$srcdir/zcc-$pkgver"
27 sed -i "s/^ \"0\.1\.0\"$/ \"$pkgver\"/" src/main.zz
28 sed -i "s/^version = \"0\.1\.0\"$/version = \"$pkgver\"/" zz.toml
29 # Native release binary.
30 zz build -p src/main.zz
31}
32
33check() {
34 cd "$srcdir/zcc-$pkgver"
35 ./src/bin/main --version
36}
37
38package() {
39 cd "$srcdir/zcc-$pkgver"
40 install -Dm755 src/bin/main "$pkgdir/usr/bin/zcc"
41 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
42 install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
43 install -Dm644 config.example.json "$pkgdir/usr/share/doc/$pkgname/config.example.json"
44 install -Dm644 config.example-zz.json "$pkgdir/usr/share/doc/$pkgname/config.example-zz.json"
45}
46

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion