Comment
The change only adds a new upstream FFmpeg patch source and applies it during prepare(), with a matching SHA-256 checksum. The source is fetched over HTTPS from the official FFmpeg forge, and there are no new build-time downloads, shell execution patterns, privilege changes, or packaging/install-script changes in this diff. I did not find evidence of malicious behavior in the reviewed hunk itself. Note: the patch file itself is not present in the checked-out tree, so I could not inspect its contents here; however, based on the PKGBUILD-only change shown, the risk appears low.
@@ -184,6 +185,7 @@ sha256sums=('8c3850283eb25fa026482078a04051e0be17347b09ef81a0849bec15a96e002e'
'4a9a672f67cc0e5dd63bd7659f5a5198cd981e60bbbc1b9a63277758be6a7fdf'
'c39addf190d25d1182c5c5658677f77ee7c1ae542969b2004441c62a425d324b'
'2c846c629ad129ae8ce50791de4f1d390714db6d6420a35406b83b9b44999d4a'
+ '6eda059a49ec07dc8d0c872c3c1fc71d8f92c5e76463380c62fe027111b3ae2e'
'04a7176400907fd7db0d69116b99de49e582a6e176b3bfb36a03e50a4cb26a36')
validpgpkeys=('FCF986EA15E6E293A5644F10B4322F04D67658D8')