zcc
The package downloads a prebuilt ZZ compiler from the same maintainer's GitHub release, which is used to build the zcc tool; while the host is not whitelisted, it is the project's official repository, and the source code is available and verifiable, reducing supply-chain risk.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads a prebuilt ZZ compiler from the same maintainer's GitHub release, which is used to build the zcc tool; while the host is not whitelisted, it is the project's official repository, and the source code is available and verifiable, reducing supply-chain risk.
PKGBUILD
# Maintainer: zaidejjo
# Generated by zcc's release workflow from PKGBUILD.template — do not edit
# in the AUR repo directly; change the template and cut a new release.
#
# The ZZ compiler arrives PREBUILT (pinned release zip, see
# packaging/zz.version in the zcc repo) — nothing is compiled except zcc
# itself, so installs take seconds, not tens of minutes.
pkgname=zcc
pkgver=0.1.0
pkgrel=1
pkgdesc='Blazing-fast code counter (tokei clone) written in ZZ'
arch=('x86_64')
url='https://github.com/zaidejjo/zcc'
license=('MIT')
depends=('glibc' 'sqlite')
makedepends=('clang' 'unzip')
source=("zcc-$pkgver-src.tar.gz::$url/releases/download/v$pkgver/zcc-$pkgver-src.tar.gz"
"zz-0.1.4-$CARCH.zip::https://github.com/zaidejjo/zz/releases/download/v0.1.4/zz-0.1.4-linux-x86_64.zip")
sha256sums=('b61716a7515ad79268efd52c15c3771b75b77df810e1b831e308dca172ffa0c2'
'ed9868ecbcc2325d63d751e3109cf204d73b51cd83ddfeb1a14e6fa852e82623')
build() {
# Prebuilt toolchain (auto-extracted flat into $srcdir by makepkg).
export PATH="$srcdir:$PATH"
# Stamp the release version (source tarball carries the tag tree).
cd "$srcdir/zcc-$pkgver"
sed -i "s/^ \"0\.1\.0\"$/ \"$pkgver\"/" src/main.zz
sed -i "s/^version = \"0\.1\.0\"$/version = \"$pkgver\"/" zz.toml
# Native release binary.
zz build -p src/main.zz
}
check() {
cd "$srcdir/zcc-$pkgver"
./src/bin/main --version
}
package() {
cd "$srcdir/zcc-$pkgver"
install -Dm755 src/bin/main "$pkgdir/usr/bin/zcc"
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
install -Dm644 config.example.json "$pkgdir/usr/share/doc/$pkgname/config.example.json"
install -Dm644 config.example-zz.json "$pkgdir/usr/share/doc/$pkgname/config.example-zz.json"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:13:36 | Low | 2 |
| 2026-10-05 23:40:58 | Low | 1 |