Package Details: collab3-vst 1.0.0-2

Git Clone URL: https://aur.archlinux.org/collab3-vst.git (read-only, click to copy)
Package Base: collab3-vst
Description: CollaB3 Tone Wheel Organ (VST)
Upstream URL: https://github.com/augustofilocamo/superOrgan
Licenses: EULA
Groups: vst-plugins, pro-audio
Submitter: None
Maintainer: None
Last Packager: None
Votes: 1
Popularity: 0.000000
First Submitted: 2021-12-20 22:02 (UTC)
Last Updated: 2022-02-02 06:21 (UTC)

Latest Comments

dvzrv commented on 2022-02-02 08:20 (UTC)

@usrmusicman: So, looking at upstream, all of their... code(?) is licensed under the terms of the GPL3.

However, you are downloading and executing a shell script that encodes a binary archive(?!).

If this software is indeed licensed under the terms of the GPL3 please engage with upstream for:

  • making available their source code instead of an encoded binary blob in a shell script (this is beyond fishy)
  • clear build instructions
  • clear installation instructions

This PKGBUILD still violates the AUR submission guidelines (as stated before) and should build the plugin from source. At this point it is still a -bin package (and a creepy one at that).

dvzrv commented on 2021-12-21 13:55 (UTC)

Please rename this package to have a -bin suffix, as it is repackaging a binary (see https://wiki.archlinux.org/title/AUR_submission_guidelines#Rules_of_submission).

Also, please make sure to provide checksums for downloaded artifacts such as an executed script (even if there are no direct download links for the actual tarballs).

Please also make sure to always quote $srcdir and $pkgdir.