apache-mod_bw
maintainer orphaned
· 4 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package builds a DSO module from source hosted on a plausible project-owned domain; the non-whitelisted host is used for source distribution, not a prebuilt binary, and the build process is transparent and standard for AUR.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds a DSO module from source hosted on a plausible project-owned domain; the non-whitelisted host is used for source distribution, not a prebuilt binary, and the build process is transparent and standard for AUR.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:25
source=("http://ivn.cl/files/source/$_pkgname-$pkgver.tgz"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Phillip Smith <pkgbuild@phs.id.au>
2
# http://github.com/fukawi2/aur-packages
3
4
### I AM ONLY THE PACKAGER, NOT THE DEVELOPER
5
### Please ask support questions about this software in one of:
6
### 1) The AUR comments; OR
7
### 2) Upstream forums/maillist etc; OR
8
### 3) The ArchLinux forums
9
### I do not always know enough about the software itself, or don't have the
10
### time to promptly respond to direct emails.
11
### If you have found a problem with the package/PKGBUILD (as opposed to
12
### the software) then please do email me or post an AUR comment.
13
14
pkgname=apache-mod_bw
15
_pkgname=mod_bw
16
pkgver=0.92
17
pkgrel=1
18
pkgdesc="DSO module for Apache that throttles HTTP traffic"
19
url="http://ivn.cl/category/apache/"
20
arch=('i686' 'x86_64')
21
license=('apache')
22
depends=('apache')
23
makedepends=('apache')
24
install="$pkgname.install"
25
source=("http://ivn.cl/files/source/$_pkgname-$pkgver.tgz"
26
'apache24.patch')
27
md5sums=('90f5e632dad5de8d49dcdb61453dcf97'
28
'23f29e631f65ba05e650a5b0cf57dba7')
29
30
_MODDIR='usr/lib/httpd/modules'
31
_DOCDIR="usr/share/doc/$pkgname"
32
33
prepare() {
34
cd "$srcdir"
35
36
# fix for apache 2.4
37
patch < "$srcdir"/apache24.patch
38
}
39
40
build() {
41
cd "$srcdir"
42
43
# make the module
44
/usr/sbin/apxs -c -o $_pkgname.so $_pkgname.c
45
}
46
47
package() {
48
cd "$srcdir"
49
50
install -Dm644 .libs/$_pkgname.so $pkgdir/$_MODDIR/$_pkgname.so
51
52
# install docs
53
install -Dm644 $_pkgname.txt $pkgdir/$_DOCDIR/$_pkgname.txt
54
}
55
56
# vim:set ts=2 sw=2 et:
57
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |