Search Criteria
Package Details: aur-security-auditor 1.4.8-1
Package Actions
| Git Clone URL: | https://aur.archlinux.org/aur-security-auditor.git (read-only, click to copy) |
|---|---|
| Package Base: | aur-security-auditor |
| Description: | Explainable security auditor for AUR packages and supply-chain risks |
| Upstream URL: | https://github.com/pacmanics/aur-security-auditor |
| Licenses: | GPL-3.0-or-later |
| Submitter: | pacmanics |
| Maintainer: | pacmanics |
| Last Packager: | pacmanics |
| Votes: | 1 |
| Popularity: | 0.49 |
| First Submitted: | 2026-08-11 21:03 (UTC) |
| Last Updated: | 2026-08-12 22:52 (UTC) |
Dependencies (12)
- binutils
- hicolor-icon-theme (hicolor-icon-theme-gitAUR)
- libcap
- pacman (pacman-gitAUR, pacman-fancy-gitAUR, pacman-selinuxAUR)
- python
- sudo (sudo-gitAUR, fudo-gitAUR, run0-sudo-shim-selinuxAUR, run0-sudo-shimAUR, run0-sudo-shim-gitAUR, doas-sudo-shimAUR, doas-sudo-shim-gitAUR, sudo-selinuxAUR, run0-sudoAUR, voixAUR, voix-binAUR)
- devtools (devtools-gitAUR, devtools-doasAUR) (optional) – build packages in an isolated clean chroot for deep scans
- git (git-gitAUR, git-glAUR, git-wd40AUR) (optional) – inspect recent AUR Git history
- libarchive (libarchive-gitAUR) (optional) – inspect built package archives with bsdtar
- namcap (namcap-gitAUR) (optional) – inspect package quality during deep scans
- xdg-utils (busking-gitAUR, xdg-utils-slockAUR, mimiAUR, mimi-gitAUR, openerAUR, mimejs-gitAUR, xdg-utils-mimeoAUR, xdg-utils-gitAUR) (optional) – automatically open the local dashboard in a browser
- zstd (zstd-gitAUR, zstd-staticAUR) (optional) – inspect local .tar.zst package source archives
Latest Comments
pacmanics commented on 2026-08-12 13:30 (UTC)
Already on it. aur-security-auditor is fixed, and I’m reviewing the rest of my packages as well. The affected ones will be moved to proper upstream repositories where necessary.
Namarrgon commented on 2026-08-12 13:15 (UTC)
Don't forget your other packages, they have the same problem.
pacmanics commented on 2026-08-12 12:07 (UTC)
Thanks for pointing this out. Fixed: upstream is now hosted on GitHub and the AUR package fetches the tagged release. The current AUR tree contains packaging files only. The initial commit still contains the old source history, which I cannot rewrite as a regular maintainer.
FabioLolix commented on 2026-08-11 22:15 (UTC)
Hi, please don't use the AUR to host code but use githuab, gitlab, codeberg, forgeio etc