AUR AI Reviewer

Review Results

Version #2592 of qownnotes · commit ef2c0801aeef · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4111

Comment

The only change in this .SRCINFO hunk is a version bump from 26.9.12 to 26.9.13. No sources, checksums, build steps, install scripts, permissions, or package metadata that would affect security were changed in the provided diff. Based on this hunk alone, there is no evidence of malicious behavior or integrity risk.

@@ -1,6 +1,6 @@
 pkgbase = qownnotes
 	pkgdesc = Plain-text file markdown note taking with Nextcloud/ownCloud integration
-	pkgver = 26.9.12
+	pkgver = 26.9.13
 	pkgrel = 1
 	url = https://www.qownnotes.org/
 	arch = i686
Risk 0/5 · Safe .SRCINFO
Result #4112

Comment

The change is a straightforward upstream version bump in .SRCINFO, updating the release tarball URL from v26.9.12 to v26.9.13 on GitHub over HTTPS. There are no new sources, no build-script changes, no added install hooks, and no integrity red flags visible in this diff. Based on the provided hunk alone, this appears low risk.

@@ -19,7 +19,7 @@ pkgbase = qownnotes
 	depends = botan
 	depends = libgit2
 	depends = libsecret
-	source = https://github.com/pbek/QOwnNotes/releases/download/v26.9.12/qownnotes-26.9.12.tar.xz
+	source = https://github.com/pbek/QOwnNotes/releases/download/v26.9.13/qownnotes-26.9.13.tar.xz
 	sha256sums = ARCHIVE-SHA256
 
 pkgname = qownnotes
Risk 0/5 · Safe PKGBUILD
Result #4113

Comment

The change is a routine version bump for a source tarball fetched over HTTPS from the upstream GitHub release page, with the checksum updated accordingly and the VCS tag pinned to a specific commit. No new build-time network access, scripts, privilege changes, or packaging behavior changes are introduced. I did not find any security-relevant red flags in this diff.

@@ -2,8 +2,8 @@
 # https://wiki.archlinux.org/title/PKGBUILD
 
 pkgname=qownnotes
-pkgver=26.9.12
-tag="ec59d40f2f07974405df572e58fde0f7efb29a8d"
+pkgver=26.9.13
+tag="666c4e848164d94816312c235adf04ce0e928b5e"
 pkgrel=1
 pkgdesc="Plain-text file markdown note taking with Nextcloud/ownCloud integration"
 arch=('i686' 'x86_64' 'armv7h' 'aarch64')
Risk 0/5 · Safe PKGBUILD
Result #4114

Comment

The change only updates the SHA-256 checksum for the upstream release tarball while keeping the source URL pinned to the official GitHub release asset over HTTPS. No build logic, install scripts, or packaging behavior changed, and there are no new network fetches or privilege-related actions. Security impact is limited to source integrity verification, and the new checksum appears to be a routine upstream version update rather than a suspicious source substitution.

@@ -13,7 +13,7 @@ groups=('qownnotes')
 depends=('qt6-base' 'qt6-svg' 'qt6-declarative' 'qt6-websockets' 'aspell' 'botan' 'libgit2' 'libsecret')
 makedepends=('qt6-tools' 'cmake')
 source=("https://github.com/pbek/QOwnNotes/releases/download/v${pkgver}/qownnotes-${pkgver}.tar.xz")
-sha256sums=('2dc7ab4ecd3c0952a0f94d7062ecc0417e92ca4d82c171131abdac7b839a977e')
+sha256sums=('0a017596de225309757728d38255ef9427eade4be0596d1eab642dc70773478d')
 
 prepare() {
     cd "${pkgname}-${pkgver}"