AUR AI Reviewer

Review Results

Version #2676 of kalu · commit 0a9f349aa055 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4432

Comment

Risk is low. The .SRCINFO update is a routine version bump from 4.7.1 to 4.7.2 with matching source and checksum changes, and it removes stale metadata entries (url, notification-daemon, replaces) that are not security-relevant in this diff. No new sources, scripts, or build-time execution paths are introduced by the .SRCINFO change itself. The only caution is that .SRCINFO is metadata-only and should match the PKGBUILD, which it does here.

@@ -1,8 +1,7 @@
 pkgbase = kalu
 	pkgdesc = Upgrade notifier w/ AUR support, watched (AUR) packages, news
-	pkgver = 4.7.1
-	pkgrel = 2
-	url = https://github.com/Thulinma/kalu
+	pkgver = 4.7.2
+	pkgrel = 1
 	install = kalu.install
 	arch = i686
 	arch = x86_64
Risk 0/5 · Safe .SRCINFO
Result #4433

Comment

The change is low risk. It only updates the upstream source tarball from 4.7.1 to 4.7.2 and refreshes the SHA-256 checksum, while removing an unnecessary runtime dependency (`notification-daemon`) and the `replaces = kalu-kde` metadata line. The source remains an HTTPS GitHub release tarball, and there are no added build-time downloads, scripts, privilege changes, or suspicious install/persistence mechanisms in this diff. I don't see evidence of supply-chain or packaging abuse in the `.SRCINFO` update itself.

@@ -17,12 +16,10 @@ pkgbase = kalu
 	depends = pacman<7.2
 	depends = curl
 	depends = libnotify
-	depends = notification-daemon
 	depends = libdbusmenu-gtk3
 	provides = kalu-kde
 	conflicts = kalu-kde
-	replaces = kalu-kde
-	source = https://github.com/Thulinma/kalu/archive/refs/tags/4.7.1.tar.gz
-	sha256sums = ea3df170d6350fe4fd60c857d8f6d887550662e473fa2dd2d71f519495d2d898
+	source = https://github.com/Thulinma/kalu/archive/refs/tags/4.7.2.tar.gz
+	sha256sums = c89515e332bc064b0a78bd00ca819ad6f7a72ae6ce2b7aa1c77cb59025469998
 
 pkgname = kalu
Risk 0/5 · Safe PKGBUILD
Result #4434

Comment

The change is low risk. It only bumps the package version, refreshes the source checksum, and removes an explicit dependency on notification-daemon plus an unused url/replaces field. The source remains the official GitHub release tarball over HTTPS, with no new build-time downloads, scripts, or privilege-related changes in the PKGBUILD diff. The existing .install script does create/delete a system group as root on install/remove, but that behavior is unchanged by this commit and is not introduced here.

@@ -1,20 +1,18 @@
 # Maintainer: Thulinma
 # Contributor: jjacky
 pkgname=kalu
-pkgver=4.7.1
-pkgrel=2
+pkgver=4.7.2
+pkgrel=1
 pkgdesc="Upgrade notifier w/ AUR support, watched (AUR) packages, news"
 arch=('i686' 'x86_64' 'aarch64')
-url="https://github.com/Thulinma/kalu"
 license=('GPL3+')
-depends=('dbus' 'polkit' 'gtk3' 'pacman>=6.1' 'pacman<7.2' 'curl' 'libnotify' 'notification-daemon' 'libdbusmenu-gtk3')
-replaces=('kalu-kde')
+depends=('dbus' 'polkit' 'gtk3' 'pacman>=6.1' 'pacman<7.2' 'curl' 'libnotify' 'libdbusmenu-gtk3')
 provides=('kalu-kde')
 conflicts=('kalu-kde')
 makedepends=('perl' 'groff')
 source=(https://github.com/Thulinma/kalu/archive/refs/tags/$pkgver.tar.gz)
 install=kalu.install
-sha256sums=('ea3df170d6350fe4fd60c857d8f6d887550662e473fa2dd2d71f519495d2d898')
+sha256sums=('c89515e332bc064b0a78bd00ca819ad6f7a72ae6ce2b7aa1c77cb59025469998')
 
 build() {
   cd "$srcdir/$pkgname-$pkgver"