AUR AI Reviewer

Review Results

Version #2605 of openapv · commit c02ad4305bec · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4166

Comment

The change is a straightforward upstream version bump in .SRCINFO from 1.1.1.0 to 1.1.2.0, with the source URL and SHA-256 checksum updated accordingly. The source remains HTTPS on the official GitHub repository, there are no new build steps, no added scripts, and no packaging/persistence red flags in this diff. Based on the provided hunk alone, this looks low risk.

@@ -1,13 +1,13 @@
 pkgbase = openapv
 	pkgdesc = The reference implementation of the APV codec
-	pkgver = 1.1.1.0
+	pkgver = 1.1.2.0
 	pkgrel = 1
 	url = https://github.com/AcademySoftwareFoundation/openapv/
 	arch = x86_64
 	license = BSD-3-Clause
 	makedepends = cmake
 	depends = glibc
-	source = https://github.com/AcademySoftwareFoundation/openapv/archive/v1.1.1.0/openapv-1.1.1.0.tar.gz
-	sha256sums = 956e6e2cc822c63af4c323bf86464f1186171314e67e9c5153f58bd875538470
+	source = https://github.com/AcademySoftwareFoundation/openapv/archive/v1.1.2.0/openapv-1.1.2.0.tar.gz
+	sha256sums = 970f65255896c906b22d7c9f9850deeee03fecf001415804848a03b6d1bbe41a
 
 pkgname = openapv
Risk 0/5 · Safe PKGBUILD
Result #4167

Comment

The change is a straightforward version bump from 1.1.1.0 to 1.1.2.0 with the corresponding source tarball checksum update. The source remains an HTTPS GitHub release archive from the upstream project, there are no new build steps, no added scripts, and no packaging or privilege-related changes. No security concerns are evident in this diff alone.

@@ -1,7 +1,7 @@
 # Maintainer: Daniel Bermond <dbermond@archlinux.org>
 
 pkgname=openapv
-pkgver=1.1.1.0
+pkgver=1.1.2.0
 pkgrel=1
 pkgdesc='The reference implementation of the APV codec'
 arch=('x86_64')
Risk 0/5 · Safe PKGBUILD
Result #4168

Comment

The change only updates the sha256 checksum for the upstream source tarball while keeping the same HTTPS GitHub release URL and no build/install logic changes. This is a normal integrity pin update and does not introduce new execution, network, privilege, or packaging risks in the reviewed hunk.

@@ -10,7 +10,7 @@ license=('BSD-3-Clause')
 depends=('glibc')
 makedepends=('cmake')
 source=("https://github.com/AcademySoftwareFoundation/openapv/archive/v${pkgver}/${pkgname}-${pkgver}.tar.gz")
-sha256sums=('956e6e2cc822c63af4c323bf86464f1186171314e67e9c5153f58bd875538470')
+sha256sums=('970f65255896c906b22d7c9f9850deeee03fecf001415804848a03b6d1bbe41a')
 
 build() {
     CFLAGS+=' -ffat-lto-objects'