arm-linux-gnueabihf-binutils-bin
Downloads a prebuilt binary tarball directly from ARM's official developer.arm.com infrastructure with a pinned sha256 checksum; the source is the project's own official release host, not a personal or swappable third-party location, so supply-chain risk is minimal.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): Downloads a prebuilt binary tarball directly from ARM's official developer.arm.com infrastructure with a pinned sha256 checksum; the source is the project's own official release host, not a personal or swappable third-party location, so supply-chain risk is minimal.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=("https://developer.arm.com/-/media/Files/downloads/gnu/${_toolchain_ver}/binrel/${_tarball}.tar.xz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: pineappletoad
pkgname=arm-linux-gnueabihf-binutils-bin
_toolchain_ver=15.2.rel1
_toolchain_date=20251217
pkgver=${_toolchain_ver}.${_toolchain_date}
pkgrel=2
pkgdesc="Cross binutils for the arm-linux-gnueabihf target (precompiled, split from ARM's official GNU toolchain release)"
arch=('x86_64')
url="https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads"
license=('GPL-2.0-or-later' 'GPL-3.0-or-later' 'LGPL-2.1-or-later')
options=('!debug' '!strip')
provides=('arm-linux-gnueabihf-binutils')
conflicts=('arm-linux-gnueabihf-binutils')
_tarball="arm-gnu-toolchain-${_toolchain_ver}-x86_64-arm-none-linux-gnueabihf"
source=("https://developer.arm.com/-/media/Files/downloads/gnu/${_toolchain_ver}/binrel/${_tarball}.tar.xz")
sha256sums=('3c65d820a6b8f677f8f6fbfc749fe00a4f16dde12341436c9df5b7092a47c0fb')
package() {
cd "${srcdir}/${_tarball}"
local _tools=(addr2line ar as c++filt dwp elfedit gprof ld ld.bfd ld.gold nm objcopy objdump ranlib readelf size strings)
install -d "${pkgdir}/usr/bin"
for _tool in "${_tools[@]}"; do
install -m755 "bin/arm-none-linux-gnueabihf-${_tool}" "${pkgdir}/usr/bin/"
done
# Arch-conventional arm-linux-gnueabihf-* symlinks alongside ARM's own
# arm-none-linux-gnueabihf-* naming - same technique the real
# arm-gnu-toolchain-*-bin AUR package uses, so anything expecting either
# naming convention finds a working binary.
cd "${pkgdir}/usr/bin"
for f in arm-none-linux-gnueabihf-*; do
ln -s "$f" "${f/arm-none-linux-gnueabihf/arm-linux-gnueabihf}"
done
cd "${srcdir}/${_tarball}"
install -d "${pkgdir}/usr/arm-none-linux-gnueabihf/bin"
cp -a arm-none-linux-gnueabihf/bin/. "${pkgdir}/usr/arm-none-linux-gnueabihf/bin/"
# lib/bfd-plugins (libdep.so) is deliberately not installed here: it
# would land at /usr/lib/bfd-plugins/libdep.so, which the system's own
# native binutils package already owns - the real arm-linux-gnueabihf-
# binutils AUR package strips all of usr/lib for the same reason
# ("collides with system installation of binutils").
install -Dm644 license.txt "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-04 03:57:33 | Low | 3 |
| 2026-09-04 03:56:15 | Medium | 2 |