#help review pkgbuild (i am mostly incapable of understanding code)

26 messages · Page 1 of 1 (latest)

thorny bison
#

im no skilled programmer in any regard but
https://aur.archlinux.org/packages/kando-bin
this pkgbuild looks safe right...?
the 1 vote and username of "zxp19821005" does not give me any good feelings
but there is absolutely no other place to get this package D:

warm inlet
#

@thorny bison why use that?

thorny bison
#

also i want to use this for a rice

#

its basically just a cool application menu thats flashy

#

this is what it is

warm inlet
#

@thorny bison what de/wm are you on?

thorny bison
#

hyprland

warm inlet
thorny bison
#

i also wanna make sure but, its not malicious right?

#

thats honestly my sole concern

#

nothing in the pkgbuild is sus i assume?

#

this might be a dumb question but i genuinely just cannot read code well so i cant just lie to myself

woven skiff
#

whenever checking pkgbuilds check : Is packages are being downloaded from legitimate upstream sources, if it's legit then it'll mostly ok

#

check arch wiki guide on how to write pkgbuild, from there match variables to make pkgbuild and check it to that package.. If you found that pacakges contains longer script than normal use .. it's under suspection

thorny bison
#

super duper tysm for the detailed response

#

i mega appreciate it 🌻

woven skiff
#

Use packages in chroot-jail env or install aura package manager : it'll scan pkgbuilds before building it

viscid cloak
#

looks fine