Hello, I'm the maintainer.

Yes, Alexander's review reads like AI generated, but still, helped me solve 
some issues, although you're right that they should've been posted in the GH 
issue tracker, as this thread was to discuss trustsight as a helper in the 6th 
layer of my proposal of the AUR security as layers (see first mail).

Answering your questions about what means what, in case you want to understand 
how trustsight works.

The dependency corpus is a local SQLite table of every dependency name the tool 
has seen across AUR packages, with a count of how often. This allows the tool 
to discern when a name is new or ordinary. The seeded/unseeded means that the 
table has been pre-filled from a shipped seed, released on Github. On a fresh 
install, it sits empty, and the tool stays silent instead of declaring all new 
deps as new. The seed acts as a "vaccine" for the dependency corpus, feeding it 
some data so it can better discern in the future.

The D series rules are dependency-graph rules that act on dependency-based 
triggers. D001 and D002 are novelty based so they stay silent on empty table, 
because they can't distinguish "new" from "no data".

About novelty tiers/score. The score is the sum of the weighted components, not 
only rules. "Tier C" components are "new" signals (new URL, new maintainer, 
etc) whose weight scales with how mature is the history, so "new maintainer" is 
a score component, not a rule by itself.

About RPC, trustsight ask AUR's RPC endpoint for package metadata. In --last 
mode a second lookup returns a trimmed record, which is why maintainer field 
can be empty sometimes.

git R100 is git's shorthand for a rename with 100% similarity, so moved or 
renamed a file, when contents are byte identical.

I'll move the defect-level follow-ups to the issue tracker. Happy to keep 
design discussion here if it's useful to the list. Feel free to AMA.

Att.

Emiliano





> Emiliano Gandini Outeda
> https://emiliano-go.com
> [email protected]


---

On Monday, September 21st, 2026 at 5:12 AM, Maarten de Vries 
<[email protected]> wrote:

> 

> On 9/21/26 00:52, Alexander Berg wrote:
> > Two corrections to my own review of TrustSight, since both went to the
> > list.
> >
> > First, the neovim-git instability is real but I described it wrongly. For
> > commit 99d9d479, inspect scores 0/100 with no findings when the local
> > dependency corpus is unseeded
> 

> What on earth is a dependency corpus? And what does it mean for a
> dependency corpus to be seeded or not?
> 

> 

> > because the D-series is deliberately silent on
> > an empty table, and 25/100 with D001, "Novel Dependency Added: optdepends
> > 'tree-sitter-cli' has never been seen in the AUR", when the corpus is
> > populated but lacks that name.
> 

> D-series? What? What empty table?
> 

> 

> > The run folds the names it just saw into its
> > own corpus, so an immediate rerun of the identical command falls back to
> > 0/100.
> 

> We have another corpus now? And names can be folded into it?
> 

> 

> > So the same command has three possible answers, but the sequence is
> > 0 and 25, not the 0/15/0 I wrote. "Maintainer first seen for this
> > package" is
> > not a rule: it is a tier-C novelty score component, and it never
> > appears in
> > --last output at all, because the second RPC lookup gets a trimmed
> > record back
> > with no maintainer field.
> 

> Interesting. I didn't know we have tiers of novelty scores we can assign
> to components. And something is looking up RPCs? Cool.
> 

> 

> >
> > Second, on qt5-styleplugins f15a54a1: it adds one new patch file and
> > renames
> > the existing one; git reports the rename as R100 with byte-identical
> > content.
> 

> What on earth is git reporting something as R100?
> 

> 

> > The new entry is the third element of source and sha512sums, not the
> > second.
> > With rename detection off git shows two additions and one deletion,
> > which is
> > where my "two patch files" came from. The finding itself stands: that
> > commit
> > still comes back as "No findings", 0/100.
> >
> > I have sent Emiliano the full reproduction material with commands and
> > verbatim
> > output for all three cases.
> >
> > Alexander Berg
> 

> 

> If this is an AI review of some project, could you please post it on the
> project issue tracker instead of the mailing list?
> 

> Perhaps some of what your AI wrote makes sense to the maintainer, but to
> me it's all gibberish. I don't think it's suitable for the mailinglist.
> 

> I apologize if I'm being grumpy, but I get a lot of AI nonsense to
> filter through at work. I hope we can keep it out of the mailinlists.
> 

> Kind regards,
> Maarten
> 

> 

> 

> 

Attachment: publickey - [email protected] - 0xF759D6D4.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to