AUR AI Reviewer

Review Results

Version #2600 of exaile · commit 34288a81a351 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4144

Comment

The change only adds two runtime dependencies in .SRCINFO: python-setproctitle and python-pynput. There are no source URL, build, install-script, or permission changes here, and .SRCINFO itself is metadata only. The added dependencies are plausible for a desktop audio player and do not by themselves indicate malicious behavior. No security issue is evident from this diff alone.

@@ -11,7 +11,9 @@ pkgbase = exaile
 	makedepends = pygobject-devel>=3.24.0
 	makedepends = help2man
 	depends = python>=3.8
+	depends = python-setproctitle
 	depends = python-bsddb
+	depends = python-pynput
 	depends = gtk3>=3.24.0
 	depends = gst-python>=1.16.0
 	depends = gst-plugins-base>=1.16.0
Risk 0/5 · Safe .SRCINFO
Result #4145

Comment

The change only adds an optdepends entry for `python-traitlets` in `.SRCINFO`. This is metadata-only and does not alter build steps, sources, checksums, install scripts, permissions, or package contents. The dependency itself is a normal Python library and the source remains the official GitHub release tarball over HTTPS. No security-relevant behavior is introduced by this diff.

@@ -45,6 +47,7 @@ pkgbase = exaile
 	optdepends = moodbar: moodbar plugin
 	optdepends = gst-plugins-bad: BPM Counter plugin
 	optdepends = python-beautifulsoup4: lyrics from lyrics.wikia.com (lyricwiki)
+	optdepends = python-traitlets: configuration
 	optdepends = ipython: ipconsole plugin
 	source = exaile-4.2.2.tar.gz::https://github.com/exaile/exaile/archive/4.2.2.tar.gz
 	sha512sums = 2cfb3e75155e6f6bcf02244b74857444cc62c00d14105a2ecd7f9148d3d1c6e3abf3b45c8b8b14676b3dc18179d8e7cb5dbdc902634fddeb5b6e839624800c66
Risk 0/5 · Safe .gitignore
Result #4146

Comment

The change only adjusts .gitignore exceptions, re-allowing .nvchecker.toml and reordering the existing whitelist entries. This does not affect build logic, packaging behavior, source integrity, or introduce any execution/persistence mechanism. No security impact is evident from the diff alone.

@@ -1,5 +1,6 @@
 *
+!.nvchecker.toml
 !.gitignore
-!.SRCINFO
 !PKGBUILD
+!.SRCINFO
 !LICENSE
Risk 0/5 · Safe .nvchecker.toml
Result #4147

Comment

The change adds an nvchecker configuration for the exaile package that points to the official GitHub repository and enables tracking the latest release. This is metadata only; it does not affect the package build, install scripts, or shipped artifacts. The source is HTTPS via GitHub and there are no signs of code execution, privilege escalation, or integrity bypass in this diff. The only minor concern is that use_latest_release=true makes version tracking follow upstream releases automatically, but that is expected for nvchecker and not a security issue by itself.

@@ -0,0 +1,4 @@
+[exaile]
+source = "github"
+github = "exaile/exaile"
+use_latest_release = true
Risk 0/5 · Safe PKGBUILD
Result #4148

Comment

The change only updates maintainer/contributor metadata in PKGBUILD and does not affect sources, build steps, dependencies, install scripts, permissions, or any executable packaging logic. No security-relevant behavior is introduced by this diff hunk.

@@ -1,4 +1,5 @@
-# Maintainer: UnicornDarkness
+# Maintainer: Rafael Dominiquini <rafaeldominiquini at gmail dot com>
+# Contributor: UnicornDarkness
 # Contributor: Tom Kwok <contact@tomkwok.com>
 # Contributor: Jorge Barroso <jorge.barroso.11 at gmail dot com>
 # Contributor: Roman Kyrylych <Roman.Kyrylych@gmail.com>
Risk 0/5 · Safe PKGBUILD
Result #4149

Comment

The change only adds runtime Python dependencies (`python-setproctitle`, `python-pynput`) and an extra documentation install for `README.md`, plus a harmless optdepends entry. The source remains pinned to an HTTPS GitHub tarball with an existing checksum, and there are no new build-time downloads, shell execution patterns, privilege escalation, or packaging writes outside `$pkgdir`. I don’t see a security issue in this diff.

@@ -14,7 +15,9 @@ arch=('any')
 url="https://exaile.org"
 license=('GPL-2.0-only')
 depends=('python>=3.8'
+	'python-setproctitle'
 	'python-bsddb'
+	'python-pynput'
 	'gtk3>=3.24.0'
 	'gst-python>=1.16.0'
 	'gst-plugins-base>=1.16.0'
Risk 0/5 · Safe PKGBUILD
Result #4150

Comment

The change is low risk. It only adds an optional runtime dependency (python-traitlets), normalizes quoting/path formatting, and installs the upstream README into the package doc directory. There are no new network fetches, privilege changes, suspicious scripts, or build-time execution paths introduced. The source URL remains HTTPS and pinned to the release tarball, and the added documentation install stays within $pkgdir.

@@ -52,26 +55,28 @@ optdepends=('udisks2: device detection'
 	'moodbar: moodbar plugin'
 	'gst-plugins-bad: BPM Counter plugin'
 	'python-beautifulsoup4: lyrics from lyrics.wikia.com (lyricwiki)'
+	'python-traitlets: configuration'
 	'ipython: ipconsole plugin')
 source=("$pkgname-$pkgver.tar.gz::https://github.com/exaile/exaile/archive/$pkgver.tar.gz")
 sha512sums=('2cfb3e75155e6f6bcf02244b74857444cc62c00d14105a2ecd7f9148d3d1c6e3abf3b45c8b8b14676b3dc18179d8e7cb5dbdc902634fddeb5b6e839624800c66')
 
-# prepare() {
-# 	cd "$srcdir/$pkgname-$pkgver"
-# 	patch -Np1 -i ../0001-xxx.patch
-# }
 
 build() {
-	cd "$srcdir/$pkgname-$pkgver"
+	cd "${srcdir}/${pkgname}-${pkgver}"
+
 	make PREFIX="/usr"
 }
 
 check() {
-	cd "$srcdir/$pkgname-$pkgver"
+	cd "${srcdir}/${pkgname}-${pkgver}"
+
 	make PYTEST=py.test test
 }
 
 package() {
-	cd "$srcdir/$pkgname-$pkgver"
-	make PREFIX="/usr" DESTDIR="$pkgdir" install
+	cd "${srcdir}/${pkgname}-${pkgver}"
+
+	make PREFIX="/usr" DESTDIR="${pkgdir}" install
+
+	install -Dm644 "README.md" "${pkgdir}/usr/share/doc/${pkgname}/README.md"
 }