Comment
The change only updates the pinned upstream commit tag and the corresponding source tarball checksum for the same official GitHub release asset. The download remains HTTPS from the project’s release page, there are no new build steps, scripts, or privilege/network changes, and no suspicious additional sources were introduced. This is a routine version-pin refresh with no evident security impact.
@@ -3,7 +3,7 @@
pkgname=qownnotes
pkgver=26.9.11
-tag="13ee3f7162c765fe0a1c5149033c09fcb7e6cb74"
+tag="caa888f98c199b13f3eaf194ff85e3187564fdf6"
pkgrel=1
pkgdesc="Plain-text file markdown note taking with Nextcloud/ownCloud integration"
arch=('i686' 'x86_64' 'armv7h' 'aarch64')