AUR AI Reviewer

Review Results

Version #2530 of codelite · commit d114ca59becc · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #3838

Comment

The only change in the provided .SRCINFO hunk is a version bump from 18.4.0 to 18.5.0. No source URLs, checksums, build commands, install scripts, permissions, or package metadata affecting trust boundaries were changed in the reviewed diff. Based on this hunk alone, there is no security signal.

@@ -1,6 +1,6 @@
 pkgbase = codelite
 	pkgdesc = Cross platform IDE for C, C++, Rust, Python, PHP and Node.js written in C++
-	pkgver = 18.4.0
+	pkgver = 18.5.0
 	pkgrel = 1
 	url = https://codelite.org/
 	arch = i686
Risk 0/5 · Safe .SRCINFO
Result #3839

Comment

The change is a straightforward version bump in .SRCINFO plus updated checksums and pinned GitHub tarball revisions for existing upstream dependencies. I do not see any new sources, protocol downgrades, build-time network fetches, install-script changes, or other persistence/privilege red flags in this diff. One source remains HTTP (wxgui.zip), but that was already present before this change and is not introduced here. Overall this diff appears low risk.

@@ -40,34 +40,34 @@ pkgbase = codelite
 	provides = codelite
 	conflicts = codelite-unstable
 	noextract = wxgui.zip
-	source = codelite-18.4.0.tar.gz::https://github.com/eranif/codelite/archive/18.4.0.tar.gz
+	source = codelite-18.5.0.tar.gz::https://github.com/eranif/codelite/archive/18.5.0.tar.gz
 	source = eranif-LuaBridge-a78d4f1.tar.gz::https://github.com/eranif/LuaBridge/tarball/a78d4f1469890eb4e795709848ebf57b002ad369
 	source = strands-agents-agent-sop-666897b.tar.gz::https://github.com/strands-agents/agent-sop/tarball/666897b95da9756d906cbfff1be123fe527b64f8
-	source = eranif-assistant-89cea94.tar.gz::https://github.com/eranif/assistant/tarball/89cea946f8404dbe0224ba10b9abb406aff0cc0a
+	source = eranif-assistant-6462fb5.tar.gz::https://github.com/eranif/assistant/tarball/6462fb53604e3c0ab69cd48a1ed5eae35cc2b32a
 	source = eranif-cc-wrapper-5346467.tar.gz::https://github.com/eranif/cc-wrapper/tarball/53464674ff2c287dfd68f05030d1d79e02d4974c
 	source = DaveGamble-cJSON-fd1ac4f.tar.gz::https://github.com/DaveGamble/cJSON/tarball/fd1ac4f1791b403af1f7350b1195ac114f9b792b
 	source = eranif-ctags-ac5c942.tar.gz::https://github.com/eranif/ctags/tarball/ac5c942b422ca6dc6cdbfd2a0c2d481af1f18f02
 	source = cubicdaiya-dtl-32567bb.tar.gz::https://github.com/cubicdaiya/dtl/tarball/32567bb9ec704f09040fb1ed7431a3d967e3df03
 	source = eranif-lexilla-8502988.tar.gz::https://github.com/eranif/lexilla/tarball/8502988a5eb83fcd281ee5a38533a9f170e6b2bf
-	source = eranif-lua-bb8dc5f.tar.gz::https://github.com/eranif/lua/tarball/bb8dc5ff01cf725dff2a8dcfe08fb0b81a9a7729
+	source = eranif-lua-d939306.tar.gz::https://github.com/eranif/lua/tarball/d939306e46fa5e4a68e9becd2f5809a40ad49fe1
 	source = eranif-wx-config-msys2-8bb3ad0.tar.gz::https://github.com/eranif/wx-config-msys2/tarball/8bb3ad01d5cbdef8d8f749d85df9fcd24d90923c
-	source = eranif-wxTerminalEmulator-eba7820.tar.gz::https://github.com/eranif/wxTerminalEmulator/tarball/eba78200448022ba5dcca72a8a1a27ccdf873462
+	source = eranif-wxTerminalEmulator-5216c4a.tar.gz::https://github.com/eranif/wxTerminalEmulator/tarball/5216c4a034bdbbc08022bbd71a03a034bd5ccf7d
 	source = eranif-wxdap-2eee320.tar.gz::https://github.com/eranif/wxdap/tarball/2eee32020c5309136358d422230abe24411d657f
 	source = jbeder-yaml-cpp-2f86d13.tar.gz::https://github.com/jbeder/yaml-cpp/tarball/2f86d13775d119edbb69af52e5f566fd65c6953b
 	source = eranif-tinyjson-d51ef6f.tar.gz::https://github.com/eranif/tinyjson/tarball/d51ef6fc646d60c1400ebde767ebfdd2b7361482
 	source = http://repos.codelite.org/wxCrafterLibs/wxgui.zip
-	sha256sums = bbb71f82926fcef0821776b404f7580fb42f1065f9f8153598d25cf3240c4d29
+	sha256sums = 238892b615fff9cbb4ba812d18cbead48def7b614cccfbd9c8f91b430f7a4a52
 	sha256sums = 1cb22a33ddacbafa9b3526e248b9abfed098d87bcbbd793774af2e816c6eb94e
 	sha256sums = 674519d58ab53166514b12446a83ac61a0641c8ce424b54ecf34653d12d636e3
-	sha256sums = cef5805a14f95eee28b0e2ea6add6e91271c08c195c1f40675a30df620f1ca5e
+	sha256sums = 8bc2cfa169087048ecd025e292733f5742f389c2f849aa50f4e102e6f9a756b0
 	sha256sums = fa90de0cadd10d875af9fc08142a46079fc024ba5afebb23fa1a966807980dc8
 	sha256sums = 70518c1b8203359c19b0313e05639568d8089cf9ffa9c9784970fdd69ab6eaad
 	sha256sums = b9277072988a8318e7b2fec411c915eee0838dd05564d10e9e9381617458dd30
 	sha256sums = baea37f9af8663240b56b634fd6e3ebd464f6b31f8ff520fc46b2ec8a8f4b3f5
 	sha256sums = 34b9a38f2b5e789a0d0aefa91df0fc4f18b1876589a78004e31b834e32821d98
-	sha256sums = 1032a78573385a7ebdbebeb88441fd041b0b377c8c2456ddf9290f11aa7ea41a
+	sha256sums = ad2db3de0fb0b81f4b58dc809935f2cd6f39ae86d8928d088bbf263506798581
 	sha256sums = 0c13192f989832a2f72bcecd5e4a81b5ae744516a6e27d5f691dbd5f00167cb2
-	sha256sums = d8525774b076ea9f60853ab0220356e2f6c411b1bdc72b7c876fd5320108e2d3
+	sha256sums = 5e0ab7841acd8106c54d4b6496d84f76f02d7e38f3aa9e0afdd6f977f6597d8f
 	sha256sums = aa53f13b9b67bd3e86dfc441389fcf576ce13f1206082885f6088eea12814998
 	sha256sums = 1603dfef3d3457d2414eab1fb29bbdba8bf350b59745fff2f4f6c2a34d81b5af
 	sha256sums = e9464a9c0a5e7bddf6759410602088d51c41faea2c39ec5759add8ddf1305687
Risk 0/5 · Safe PKGBUILD
Result #3840

Comment

The change is a routine version bump for codelite from 18.4.0 to 18.5.0, with corresponding updates to pinned submodule commit IDs and source checksums. The sources remain HTTPS GitHub tarballs and the package continues to pin exact revisions rather than floating branches. I do note one source URL is still plain HTTP (wxgui.zip from repos.codelite.org), but that issue already existed in the prior PKGBUILD and is not introduced by this diff. No new build-time network fetches, privilege escalation, install-script changes, or suspicious packaging behavior are introduced here.

@@ -24,7 +24,7 @@
 #
 _pkg_user="eranif"
 _pkg_name="codelite"
-_pkg_ver="18.4.0"
+_pkg_ver="18.5.0"
 #_commit="bf6820c7c8bece16c857f5a992aff23ac4ddc1ee"
 
 # pkg
Risk 0/5 · Safe PKGBUILD
Result #3841

Comment

The change only updates commented submodule commit references in PKGBUILD metadata. There are no functional build-script changes, no new sources, no network/download behavior, and no packaging/install logic affected. I see no security impact from this diff alone.

@@ -56,19 +56,20 @@ _pkg_src_res="${_pkg_name_ident}.tar.gz::https://github.com/${_pkg_user}/${_pkg_
 
 # git submodule | sed -E 's/^ (.*) (.*) /\2  \t \1/g'
 
+# git submodule:
 #  a78d4f1469890eb4e795709848ebf57b002ad369 submodules/LuaBridge (heads/master)
 #  666897b95da9756d906cbfff1be123fe527b64f8 submodules/agent-sop (v1.1.2)
-#  89cea946f8404dbe0224ba10b9abb406aff0cc0a submodules/assistant (remotes/origin/HEAD)
+#  6462fb53604e3c0ab69cd48a1ed5eae35cc2b32a submodules/assistant (remotes/origin/HEAD)
 #  53464674ff2c287dfd68f05030d1d79e02d4974c submodules/cc-wrapper (remotes/origin/HEAD)
 #  1da23a3e8119ec5cce4f9388e91b065e20bf06f5 submodules/doctest (v2.4.12)
 #  32567bb9ec704f09040fb1ed7431a3d967e3df03 submodules/dtl (v1.21)
 # -1d9a9ca8841ac0cd591c95b162301d2502641901 submodules/hunspell
 #  8502988a5eb83fcd281ee5a38533a9f170e6b2bf submodules/lexilla (remotes/origin/HEAD)
 # -854795c654eda518ed6de6c1ebb4e2107fcb2e73 submodules/libssh
-#  bb8dc5ff01cf725dff2a8dcfe08fb0b81a9a7729 submodules/lua (heads/master)
+#  d939306e46fa5e4a68e9becd2f5809a40ad49fe1 submodules/lua (remotes/origin/HEAD)
 # -7042229f977ca801983116593b2bbd73ae7f2657 submodules/openssl-cmake
 # -8bb3ad01d5cbdef8d8f749d85df9fcd24d90923c submodules/wx-config-msys2
-#  eba78200448022ba5dcca72a8a1a27ccdf873462 submodules/wxTerminalEmulator (heads/main-140-geba7820)
+#  5216c4a034bdbbc08022bbd71a03a034bd5ccf7d submodules/wxTerminalEmulator (v1.0.0-7-g5216c4a)
 #  2eee32020c5309136358d422230abe24411d657f submodules/wxdap (remotes/origin/HEAD)
 #  2f86d13775d119edbb69af52e5f566fd65c6953b submodules/yaml-cpp (0.8.0-74-g2f86d13)
 # -0f51fb4933fc9ce18199cb2554dacea8033e7fd3 submodules/zlib
Risk 0/5 · Safe PKGBUILD
Result #3842

Comment

The change is a routine upstream version/submodule refresh in PKGBUILD: it updates the main package version and several pinned git submodule commits, plus corresponding source checksums. The source URLs remain HTTPS and point to the expected upstream GitHub/repo.codelite.org locations; there are no new build-time downloads, shell pipelines, privilege escalations, or install-script/systemd changes in the reviewed hunk. The only notable issue is that one source URL in the existing PKGBUILD still uses plain HTTP (`http://repos.codelite.org/wxCrafterLibs/wxgui.zip`), but that is pre-existing and not introduced by this diff. No evidence of malicious behavior in the changed lines.

@@ -97,7 +98,7 @@ _agent_sop_pkg_src_res="${_agent_sop_pkg_name_ident}.tar.gz::https://github.com/
 # submodules/assistant: ssh://github.com/eraniff/codelite-assistant.git
 _assistant_pkg_user="${_pkg_user}"
 _assistant_pkg_name="assistant"
-_assistant_pkg_ident="89cea946f8404dbe0224ba10b9abb406aff0cc0a"
+_assistant_pkg_ident="6462fb53604e3c0ab69cd48a1ed5eae35cc2b32a"
 _assistant_pkg_name_ident="${_assistant_pkg_user}-${_assistant_pkg_name}-${_assistant_pkg_ident:0:7}"
 _assistant_pkg_src_res="${_assistant_pkg_name_ident}.tar.gz::https://github.com/${_assistant_pkg_user}/${_assistant_pkg_name}/tarball/${_assistant_pkg_ident}"
 
Risk 0/5 · Safe PKGBUILD
Result #3843

Comment

The change only updates pinned upstream/submodule revisions and corresponding checksums in PKGBUILD. The new source URLs remain HTTPS and point to the same upstream GitHub repositories; there are no new build-time network fetches, shell execution patterns, privilege escalation, install-script changes, or packaging-path changes introduced by this diff. The only notable issue is that one source URL in the package still uses plain HTTP elsewhere in the file, but that is pre-existing and not part of this hunk. For the reviewed change itself, risk is low.

@@ -150,7 +151,7 @@ _lexilla_pkg_src_res="${_lexilla_pkg_name_ident}.tar.gz::https://github.com/${_l
 # submodules/lua: https://github.com/eranif/lua.git
 _lua_pkg_user="${_pkg_user}"
 _lua_pkg_name="lua"
-_lua_pkg_ident="bb8dc5ff01cf725dff2a8dcfe08fb0b81a9a7729"
+_lua_pkg_ident="d939306e46fa5e4a68e9becd2f5809a40ad49fe1"
 _lua_pkg_name_ident="${_lua_pkg_user}-${_lua_pkg_name}-${_lua_pkg_ident:0:7}"
 _lua_pkg_src_res="${_lua_pkg_name_ident}.tar.gz::https://github.com/${_lua_pkg_user}/${_lua_pkg_name}/tarball/${_lua_pkg_ident}"
 
Risk 0/5 · Safe PKGBUILD
Result #3844

Comment

The change is a routine upstream version/submodule refresh in PKGBUILD: it updates pinned commit IDs for vendored submodules and corresponding source checksums, and it does not introduce new build-time network fetches, shell execution, privilege escalation, or packaging changes. One source URL remains HTTP in the existing PKGBUILD, but that is pre-existing and not introduced by this diff. No obvious supply-chain red flags are present in the reviewed hunk.

@@ -166,7 +167,7 @@ _wxcfg_pkg_src_res="${_wxcfg_pkg_name_ident}.tar.gz::https://github.com/${_wxcfg
 # submodules/wxTerminalEmulator: https://github.com/eranif/wxTerminalEmulator.git
 _wxterm_pkg_user="${_pkg_user}"
 _wxterm_pkg_name="wxTerminalEmulator"
-_wxterm_pkg_ident="eba78200448022ba5dcca72a8a1a27ccdf873462"
+_wxterm_pkg_ident="5216c4a034bdbbc08022bbd71a03a034bd5ccf7d"
 _wxterm_pkg_name_ident="${_wxterm_pkg_user}-${_wxterm_pkg_name}-${_wxterm_pkg_ident:0:7}"
 _wxterm_pkg_src_res="${_wxterm_pkg_name_ident}.tar.gz::https://github.com/${_wxterm_pkg_user}/${_wxterm_pkg_name}/tarball/${_wxterm_pkg_ident}"
 
Risk 1/5 · Low PKGBUILD
Result #3845

Comment

The change is a routine upstream version bump with corresponding checksum updates and submodule commit pin updates. I do note one source URL remains HTTP (`http://repos.codelite.org/wxCrafterLibs/wxgui.zip`), which is a supply-chain integrity weakness because it permits MITM tampering, but this URL was already present before this diff and is not introduced by the change under review. No new build-time network fetches, scripts, privilege escalation, or suspicious packaging behavior are added in this hunk.

@@ -267,18 +268,18 @@ source=(
     "http://repos.codelite.org/wxCrafterLibs/wxgui.zip"
   )
 
-sha256sums=('bbb71f82926fcef0821776b404f7580fb42f1065f9f8153598d25cf3240c4d29'
+sha256sums=('238892b615fff9cbb4ba812d18cbead48def7b614cccfbd9c8f91b430f7a4a52'
             '1cb22a33ddacbafa9b3526e248b9abfed098d87bcbbd793774af2e816c6eb94e'
             '674519d58ab53166514b12446a83ac61a0641c8ce424b54ecf34653d12d636e3'
-            'cef5805a14f95eee28b0e2ea6add6e91271c08c195c1f40675a30df620f1ca5e'
+            '8bc2cfa169087048ecd025e292733f5742f389c2f849aa50f4e102e6f9a756b0'
             'fa90de0cadd10d875af9fc08142a46079fc024ba5afebb23fa1a966807980dc8'
             '70518c1b8203359c19b0313e05639568d8089cf9ffa9c9784970fdd69ab6eaad'
             'b9277072988a8318e7b2fec411c915eee0838dd05564d10e9e9381617458dd30'
             'baea37f9af8663240b56b634fd6e3ebd464f6b31f8ff520fc46b2ec8a8f4b3f5'
             '34b9a38f2b5e789a0d0aefa91df0fc4f18b1876589a78004e31b834e32821d98'
-            '1032a78573385a7ebdbebeb88441fd041b0b377c8c2456ddf9290f11aa7ea41a'
+            'ad2db3de0fb0b81f4b58dc809935f2cd6f39ae86d8928d088bbf263506798581'
             '0c13192f989832a2f72bcecd5e4a81b5ae744516a6e27d5f691dbd5f00167cb2'
-            'd8525774b076ea9f60853ab0220356e2f6c411b1bdc72b7c876fd5320108e2d3'
+            '5e0ab7841acd8106c54d4b6496d84f76f02d7e38f3aa9e0afdd6f977f6597d8f'
             'aa53f13b9b67bd3e86dfc441389fcf576ce13f1206082885f6088eea12814998'
             '1603dfef3d3457d2414eab1fb29bbdba8bf350b59745fff2f4f6c2a34d81b5af'
             'e9464a9c0a5e7bddf6759410602088d51c41faea2c39ec5759add8ddf1305687'