AUR AI Reviewer

Review Results

Version #2672 of protonup-qt · commit 80f915780c59 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4409

Comment

The change only bumps pkgrel from 1 to 2 in .SRCINFO, with no source, build, install-script, dependency, or packaging logic changes. This is a metadata-only rebuild marker and does not introduce any new security risk on its own.

@@ -1,7 +1,7 @@
 pkgbase = protonup-qt
 	pkgdesc = Install and manage GE-Proton, Luxtorpeda & more for Steam, Lutris and Heroic
 	pkgver = 2.15.1
-	pkgrel = 1
+	pkgrel = 2
 	url = https://davidotek.github.io/protonup-qt
 	arch = any
 	license = GPL-3.0-or-later
Risk 0/5 · Safe .SRCINFO
Result #4410

Comment

The change adds a new upstream-hosted patch source and applies it during prepare(). The patch is fetched over HTTPS from the project’s GitHub PR page, which is not inherently suspicious, and the PKGBUILD still verifies it with a pinned SHA-256. I don’t see any evidence in the diff of shell execution, privilege escalation, network access during build, or packaging outside $pkgdir. The only risk is the usual trust in an external patch, but based on the reviewed metadata alone this looks like a routine packaging update with low security impact.

@@ -36,6 +36,8 @@ pkgbase = protonup-qt
 	optdepends = xxd: required for SteamTinkerLaunch
 	optdepends = yad: required for SteamTinkerLaunch
 	source = protonup-qt-2.15.1.tar.gz::https://github.com/DavidoTek/ProtonUp-Qt/archive/refs/tags/v2.15.1.tar.gz
+	source = https://github.com/DavidoTek/ProtonUp-Qt/pull/647.patch
 	sha256sums = 7028c0f3451fcb69f384ba0687b58a973b35fab2b0a64d5435eb1f782f09ea08
+	sha256sums = 9cbbea6c9e600ebe2ecb85ec4ebf5d00a48fdaf3d8c2fc88288d26e9a206280d
 
 pkgname = protonup-qt
Risk 0/5 · Safe PKGBUILD
Result #4411

Comment

This change only bumps pkgrel from 1 to 2 in PKGBUILD and does not alter sources, build steps, dependencies, install scripts, permissions, or any runtime behavior. No security-relevant changes are present in the reviewed hunk.

@@ -2,7 +2,7 @@
 pkgname=protonup-qt
 _app_id=net.davidotek.pupgui2
 pkgver=2.15.1
-pkgrel=1
+pkgrel=2
 pkgdesc="Install and manage GE-Proton, Luxtorpeda & more for Steam, Lutris and Heroic"
 arch=('any')
 url="https://davidotek.github.io/protonup-qt"
Risk 2/5 · Moderate PKGBUILD
Result #4412

Comment

The change adds a new build-time patch source fetched directly from a GitHub pull request URL and applies it in prepare(). This is not inherently malicious, but it does expand the trust boundary beyond the upstream release tarball to an unpinned, mutable PR artifact. I could not inspect the patch contents from the repository checkout because the patch file is not present locally, so there is some integrity risk in relying on a remote PR patch rather than an upstream release/tagged commit or a vendored patch in-tree. No obvious shell execution, privilege escalation, or install-script persistence is introduced in the PKGBUILD itself.

@@ -45,8 +45,17 @@ optdepends=(
   'xxd: required for SteamTinkerLaunch'
   'yad: required for SteamTinkerLaunch'
 )
-source=("$pkgname-$pkgver.tar.gz::https://github.com/DavidoTek/ProtonUp-Qt/archive/refs/tags/v$pkgver.tar.gz")
-sha256sums=('7028c0f3451fcb69f384ba0687b58a973b35fab2b0a64d5435eb1f782f09ea08')
+source=("$pkgname-$pkgver.tar.gz::https://github.com/DavidoTek/ProtonUp-Qt/archive/refs/tags/v$pkgver.tar.gz"
+        'https://github.com/DavidoTek/ProtonUp-Qt/pull/647.patch')
+sha256sums=('7028c0f3451fcb69f384ba0687b58a973b35fab2b0a64d5435eb1f782f09ea08'
+            '9cbbea6c9e600ebe2ecb85ec4ebf5d00a48fdaf3d8c2fc88288d26e9a206280d')
+
+prepare() {
+  cd "ProtonUp-Qt-$pkgver"
+
+  # Support proton-wineland
+  patch -Np1 -i ../647.patch
+}
 
 build() {
   cd "ProtonUp-Qt-$pkgver"