AUR AI Reviewer

Review Results

Version #2659 of genymotion · commit 0aadd49c2a34 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4357

Comment

The only change in this .SRCINFO hunk is a version bump from 3.10.0 to 3.11.0. No sources, checksums, build steps, install scripts, or package metadata affecting execution/persistence were changed in the provided diff. On its face this is a routine version update with no security red flags in the reviewed hunk.

@@ -1,6 +1,6 @@
 pkgbase = genymotion
 	pkgdesc = Complete set of tools that provides a virtual environment for Android.
-	pkgver = 3.10.0
+	pkgver = 3.11.0
 	pkgrel = 1
 	url = http://www.genymotion.com/
 	install = genymotion.install
Risk 0/5 · Safe .SRCINFO
Result #4358

Comment

The change is a straightforward upstream version bump in .SRCINFO from genymotion 3.10.0 to 3.11.0, with the source URL and checksum updated accordingly. The source remains an HTTPS download from the vendor’s official domain, and there are no new build steps, scripts, or privilege-related artifacts introduced in this diff. Based on the provided hunk alone, I do not see evidence of supply-chain tampering or malicious behavior.

@@ -17,8 +17,8 @@ pkgbase = genymotion
 	optdepends = virtualbox
 	options = !strip
 	source = genymotion.desktop
-	source = https://dl.genymotion.com/releases/genymotion-3.10.0/genymotion-3.10.0-linux_x64.run
+	source = https://dl.genymotion.com/releases/genymotion-3.11.0/genymotion-3.11.0-linux_x64.run
 	sha256sums = cfe3db36490d38a0331a64f50e85c432994e4543f48d2719e7feaee9f442f6e1
-	sha256sums = cb9924009a51b7d10e6009a0a2cd3e5fa5c53e0776cf65c4b42abbeaf015b7c7
+	sha256sums = 8cd727af40b437a50674df6a66a4671599c986ea3f16de63fc21bbb394ca052f
 
 pkgname = genymotion
Risk 0/5 · Safe PKGBUILD
Result #4359

Comment

The change is a straightforward version bump in PKGBUILD from 3.10.0 to 3.11.0, with the corresponding upstream release URL and checksum updated. I do not see any new sources, build-time network fetches, privilege escalation, install-script changes, or other suspicious packaging behavior introduced by this diff. Risk is low, though the package still relies on a vendor-provided .run installer and !strip, which are pre-existing concerns rather than introduced by this change.

@@ -7,7 +7,7 @@
 # Contributor: Andrea Cattaneo <andrea.cattaneo.dev@gmail.com>
 
 pkgname=genymotion
-pkgver=3.10.0
+pkgver=3.11.0
 pkgrel=1
 pkgdesc="Complete set of tools that provides a virtual environment for Android."
 arch=('x86_64')
Risk 0/5 · Safe PKGBUILD
Result #4360

Comment

The change only updates the SHA-256 checksum for the upstream Genymotion installer in PKGBUILD. The source URL remains HTTPS and points to the official Genymotion release host, with no new build steps, scripts, or privilege-related changes. I did not find any added network fetches, command execution, or packaging behavior changes in this diff hunk. Risk is low and limited to trust in the new upstream artifact checksum.

@@ -21,7 +21,7 @@ options=('!strip')
 source=("genymotion.desktop"
         "https://dl.genymotion.com/releases/genymotion-${pkgver}/${pkgname}-${pkgver}-linux_x64.run")
 sha256sums=('cfe3db36490d38a0331a64f50e85c432994e4543f48d2719e7feaee9f442f6e1'
-            'cb9924009a51b7d10e6009a0a2cd3e5fa5c53e0776cf65c4b42abbeaf015b7c7')
+            '8cd727af40b437a50674df6a66a4671599c986ea3f16de63fc21bbb394ca052f')
 
 package(){
   install -d "${pkgdir}/opt/${pkgname}"