Comment
The change is a routine metadata refresh in .SRCINFO for a new upstream release: version bump, updated source URL, and corresponding checksum updates for the release zip and the aseprite-strings git source. All sources remain HTTPS and pinned to a specific commit/tag; there are no new scripts, binaries, install hooks, or build-time network behaviors introduced by this diff. I do note that .SRCINFO is only generated metadata, so the security-relevant question is whether the underlying PKGBUILD changed safely, but within the provided diff there are no red flags.
@@ -50,10 +50,10 @@ pkgbase = aseprite
source = shared_libjpeg-turbo.patch
source = change_use_of_removed_intrinsic.patch
source = fmt-12.2.0-include-format.patch
- sha256sums = 3895afca60608e86ffbba20c32af95a6e59f8d7ebe6d2617236f159b42176bfe
+ sha256sums = 438e7a1571990383beca761eca829402f14f225e164730eb2edc71b2e9566e58
sha256sums = c2a567d6b8bb933a92615cbdee0de268d02c3a06863337ee8822eedab9ed66ba
sha256sums = b52f179a687ef2f91a52b696ab6581f4a37df5e88cb22040fa1ec6567cf0ebb1
- sha256sums = e2021cabe800b033afb799bc24f51e4b09cfb4d76afca4cf44f1cc05fb88bdf8
+ sha256sums = 883d1b25014deded64c3baa8e680dc3e2e486ca7b9c9116015c3cc557c2af781
sha256sums = 8b14e36939e930de581e95abf0591645aa0fcfd47161cf88b062917dbaaef7f9
sha256sums = c3591d376180d99ff8001c3d549c0bd18ef5e4d95f1755ccaa8e2fd65dd5d2b3
sha256sums = 96d75ecc951712e80734f476511658fcc3c91fc1655fe9a01453c3fc8c2a9274