AUR AI Reviewer

Review Results

Version #2665 of gallery-dl · commit a287148ff73e · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4378

Comment

The only change in this .SRCINFO hunk is a version bump from 1.32.14 to 1.32.15. No sources, checksums, build steps, install scripts, permissions, or metadata affecting trust boundaries were changed in the reviewed diff. On its face this is a routine package update with no security red flags in the provided change.

@@ -1,6 +1,6 @@
 pkgbase = gallery-dl
 	pkgdesc = Command-line program to download image-galleries and collections from several image hosting sites
-	pkgver = 1.32.14
+	pkgver = 1.32.15
 	pkgrel = 1
 	url = https://codeberg.org/mikf/gallery-dl
 	arch = any
Risk 0/5 · Safe .SRCINFO
Result #4379

Comment

The change is a straightforward version bump in .SRCINFO from v1.32.14 to v1.32.15, with the corresponding source checksum updated. The source remains the official upstream Codeberg repository over HTTPS and is still pinned to a signed tag, with no new build steps, scripts, or packaging metadata changes that would introduce execution or persistence risks. No security-relevant red flags are present in this diff alone.

@@ -27,8 +27,8 @@ pkgbase = gallery-dl
 	optdepends = python-psycopg: PostgreSQL support
 	optdepends = python-truststore: Support using system certificates
 	optdepends = python-jinja: Jinja template support
-	source = git+https://codeberg.org/mikf/gallery-dl.git#tag=v1.32.14?signed
+	source = git+https://codeberg.org/mikf/gallery-dl.git#tag=v1.32.15?signed
 	validpgpkeys = 3E09F5908333DD83DBDCE7375680CA389D365A88
-	sha512sums = 666285e4e68900bc0463e6508423c3e4e318e9d38dff45f71e5d6c1401c7f99f6169617698c2f29f38458a141315697956415dab96d150a38d34345c7a8013e2
+	sha512sums = c4c40bfd561585c5078fb79da6c590212c8d4de066cd5d43f6cb8befa3691ba404955fffc7e22d88948c48054cb9eceded92df1161fb77d9e46dc859f8b85c56
 
 pkgname = gallery-dl
Risk 0/5 · Safe PKGBUILD
Result #4380

Comment

The change is a routine version bump in PKGBUILD from 1.32.14 to 1.32.15, with the source tag and sha512 checksum updated accordingly. No new sources, build steps, install scripts, or privilege/network-related logic were introduced in this diff. Based on the provided hunk, there are no security red flags beyond the normal trust in the upstream signed tag and checksum update.

@@ -2,7 +2,7 @@
 # Contributor: LLL2yu <lll2yu@protonmail.com>
 
 pkgname=gallery-dl
-pkgver=1.32.14
+pkgver=1.32.15
 pkgrel=1
 pkgdesc='Command-line program to download image-galleries and collections from several image hosting sites'
 arch=(any)
Risk 0/5 · Safe PKGBUILD
Result #4381

Comment

The change is a routine version bump from 1.32.14 to 1.32.15 with the corresponding sha512 checksum update. The source remains the upstream signed git tag over HTTPS, with the same PGP key pinning and no new build steps, network fetches, install scripts, or packaging changes. I do not see any added supply-chain, persistence, or privilege-escalation risk in this diff.

@@ -29,7 +29,7 @@ optdepends=(
 )
 source=(git+"${url}".git#tag=v"${pkgver}"?signed)
 validpgpkeys=(3E09F5908333DD83DBDCE7375680CA389D365A88) #Mike Fährmann
-sha512sums=('666285e4e68900bc0463e6508423c3e4e318e9d38dff45f71e5d6c1401c7f99f6169617698c2f29f38458a141315697956415dab96d150a38d34345c7a8013e2')
+sha512sums=('c4c40bfd561585c5078fb79da6c590212c8d4de066cd5d43f6cb8befa3691ba404955fffc7e22d88948c48054cb9eceded92df1161fb77d9e46dc859f8b85c56')
 
 prepare() {
     # Clean out old wheels etc.