AUR Report Card
Generated reports on the quality of PKGBUILDs in the Arch User Repository (AUR). Reports are generated by statically analyzing the PKGBUILD files using pkglint.
- scanned
- {{.Generated}}
- packages
- {{.Total}}
- findings
- {{.Findings}}
- auto-fixable
- {{.Fixable}}
- drifted
- {{.Drifted}}
What a grade means
The grade measures hygiene: are sources pinned to something that can't change underneath you, does the build stay off the network, and can a reader follow what the package does without running it? That is all it measures.
It is not a malware verdict. An F means read this PKGBUILD before you build it. An A means nothing stood out to a parser — not that the package is safe. Static analysis cannot catch a malicious upstream release pinned with a perfectly valid checksum.
No package matches that filter.
{{/* The table above is the corpus's head, not the corpus, so say so and say where the rest is. With JavaScript the filter reaches every package once roster.json lands and site.js rewrites this line to match; the alphabetical pages are the answer that does not depend on it. The two cases are not cosmetic: a scan bounded by -budget can leave fewer packages than the table holds, and claiming to show "the 596 most-voted of 596" would describe a slice that isn't one. */}}{{if lt .Shown .Total}}Showing the {{.Shown}} most-voted of {{.Total}} packages.{{else}}All {{.Total}} packages.{{end}} Browse {{if lt .Shown .Total}}all {{.Total}} {{end}}alphabetically.