AUR AI Reviewer

Review Results

Version #2593 of x264-git · commit aa859cd7caa4 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4115

Comment

The change is limited to .SRCINFO metadata: it updates the VCS snapshot version, narrows the license tag from generic GPL to GPL-2.0-only, and removes l-smash from makedepends while adding an explicit glibc runtime dependency. There are no new sources, build commands, install scripts, or privilege/network-related changes. This does not introduce an obvious supply-chain or persistence risk in the reviewed hunk.

@@ -1,13 +1,13 @@
 pkgbase = x264-git
 	pkgdesc = Open Source H.264/AVC video encoder (git version)
-	pkgver = 161.r3042.gb3aadb76
+	pkgver = 165.r3223.g0480cb05
 	pkgrel = 1
 	url = https://www.videolan.org/developers/x264.html
 	arch = x86_64
-	license = GPL
+	license = GPL-2.0-only
 	makedepends = git
 	makedepends = nasm
-	makedepends = l-smash
+	depends = glibc
 	depends = liblsmash.so
 	provides = x264
 	provides = libx264
Risk 0/5 · Safe .SRCINFO
Result #4116

Comment

The change only removes a trailing blank line from .SRCINFO. This is metadata-only and does not affect sources, build steps, install scripts, permissions, or package contents. No security-relevant behavior is introduced.

@@ -24,4 +24,3 @@ pkgbase = x264-git
 	sha256sums = SKIP
 
 pkgname = x264-git
-
Risk 0/5 · Safe PKGBUILD
Result #4117

Comment

The change is low risk. It only updates the package version and adjusts metadata/dependencies: license is clarified to GPL-2.0-only, glibc is added as an explicit runtime dependency, and the build dependency on l-smash is removed from makedepends while the runtime soname dependency remains. There are no new sources, no build-time network fetches, no install script changes, and no suspicious packaging actions or privilege/persistence mechanisms in this hunk.

@@ -13,14 +13,18 @@
 # 10-bit, please see, e.g.: https://gist.github.com/l4n9th4n9/4459997
 
 pkgname=x264-git
-pkgver=161.r3042.gb3aadb76
+pkgver=165.r3223.g0480cb05
 pkgrel=1
 arch=('x86_64')
 pkgdesc='Open Source H.264/AVC video encoder (git version)'
 url='https://www.videolan.org/developers/x264.html'
-license=('GPL')
-depends=('liblsmash.so')
-makedepends=('git' 'nasm' 'l-smash')
+license=('GPL-2.0-only')
+depends=(
+    'glibc'
+    'liblsmash.so')
+makedepends=(
+    'git'
+    'nasm')
 provides=('x264' 'libx264' 'libx264-git' 'libx264.so')
 conflicts=('x264' 'libx264' 'libx264-10bit' 'libx264-all')
 replaces=('libx264-git' 'libx264-10bit-git' 'libx264-all-git')
Risk 0/5 · Safe PKGBUILD
Result #4118

Comment

The change is low risk. It only adjusts build directory paths after moving the configure invocation to the source tree root, and adds packaging of bash completion plus renaming the 10-bit binary/completion file. I do not see any new network access, privilege escalation, suspicious downloads, or installation outside $pkgdir. The source remains pinned to the official Videolan Git repository over HTTPS, and the diff does not introduce any new executable code beyond standard build/install commands.

@@ -28,7 +32,7 @@ source=('git+https://code.videolan.org/videolan/x264.git')
 sha256sums=('SKIP')
 
 prepare() {
-    mkdir -p x264/build-{8,10}bit
+    mkdir -p build-{8,10}bit
 }
 
 pkgver() {
Risk 0/5 · Safe PKGBUILD
Result #4119

Comment

The change is low risk. It only refactors the build/package steps for the existing upstream x264 git source: it creates build directories in a simpler location, reuses a common configure option array, and adds installation/renaming of bash completion files alongside the already-existing 8-bit/10-bit split binaries. The source remains the official Videolan HTTPS git repo, there are no new network fetches, no shell-eval/obfuscation, no privilege escalation, and no writes outside $pkgdir during packaging. I do note the package now installs bash completion via an upstream make target, but that is a normal local build artifact and is still staged into $pkgdir. No malicious persistence or supply-chain red flags are evident in this diff.

@@ -38,49 +42,46 @@ pkgver() {
 }
 
 build() {
+    local -a _common_opts=(
+        '--prefix=/usr'
+        '--enable-shared'
+        '--enable-lto'
+        '--enable-pic'
+        '--disable-avs'
+        '--disable-swscale'
+        '--disable-lavf'
+        '--disable-gpac')
+    
     printf '%s\n' '  -> Building for 8-bit...'
-    cd x264/build-8bit
-    ../configure \
-        --prefix='/usr' \
-        --enable-shared \
-        --bit-depth='8' \
-        --enable-lto \
-        --enable-pic \
-        --disable-avs \
-        --disable-swscale \
-        --disable-lavf \
-        --disable-gpac
+    cd build-8bit
+    ../x264/configure \
+        "${_common_opts[@]}" \
+        --bit-depth='8'
     make
     
     printf '%s\n' '  -> Building for 10-bit...'
-    cd "${srcdir}/x264/build-10bit"
-    ../configure \
-        --prefix='/usr' \
+    cd "${srcdir}/build-10bit"
+    ../x264/configure \
+        "${_common_opts[@]}" \
         --libdir='/usr/lib/x264-10bit' \
         --includedir='/usr/include/x264-10bit' \
-        --enable-shared \
-        --bit-depth='10' \
-        --enable-lto \
-        --enable-pic \
-        --disable-avs \
-        --disable-swscale \
-        --disable-lavf \
-        --disable-gpac
+        --bit-depth='10'
     make
 }
 
 package() {
-    cd x264
+    export BASHCOMPLETIONSDIR='/usr/share/bash-completion/completions'
     
     local _depth
     for _depth in 10 8
     do
         printf '%s\n' "  -> Installing for ${_depth}-bit..."
-        make -C "build-${_depth}bit" DESTDIR="$pkgdir" install-cli install-lib-shared
+        make -C "build-${_depth}bit" DESTDIR="$pkgdir" install-cli install-lib-shared install-bashcompletion
         
-        if [ "$_depth" -eq '10' ] 
+        if [ "$_depth" -eq '10' ]
         then
-            mv "${pkgdir}/usr/bin/x264" "${pkgdir}/usr/bin/x264-${_depth}bit"
+            mv "${pkgdir}/usr/bin/x264"{,"-${_depth}bit"}
+            mv "${pkgdir}/usr/share/bash-completion/completions/x264"{,"-${_depth}bit"}
         fi
     done
 }