Source should use commit ID instead of git tag
The PKGBUILD should probably use a commit ID instead of relying on git tags, to make this as robust and reproducible as possible even in case a potentially malicious upstream might tamper with the git tags.
//EDIT: This is also recommended in the Archlinux package guidelines, btw.
Edited by Pascal Ernster