ascd
maintainer orphaned
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is downloaded from the project's official host (dockapps.net), which is not on the whitelist but plausibly legitimate; the package builds from source and the worst case of a swapped tarball is limited to code execution during build, but no remote code execution or exfiltration is present.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the project's official host (dockapps.net), which is not on the whitelist but plausibly legitimate; the package builds from source and the worst case of a swapped tarball is limited to code execution during build, but no remote code execution or exfiltration is present.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source=("http://www.dockapps.net/download/${pkgname}-${pkgver}+lib-src.tgz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Brian Bidulock <bidulock@openss7.org>
2
3
pkgname=ascd
4
pkgver=0.13.2
5
pkgrel=1
6
pkgdesc="A CD play that can be docked with Afterstep and Window Maker"
7
arch=('i686' 'x86_64')
8
url="http://www.dockapps.net/ascd"
9
license=('GPL')
10
depends=('libxpm')
11
source=("http://www.dockapps.net/download/${pkgname}-${pkgver}+lib-src.tgz")
12
md5sums=('SKIP')
13
14
prepare() {
15
cd ${pkgname}-${pkgver}+lib-src
16
sed -i -e 's,bytesex.h,cdio/bytesex.h,;t' \
17
ascd/workman/wm_cdda.h \
18
libworkman/include/wm_cdda.h
19
sed -i -e '/InstallMultiple/s,(THEMESDIR),(THEMESDIR)/themes-manual.ps.gz,;t' \
20
ascd/Imakefile
21
sed -i -e '/^install::/,$s,\$(THEMESDIR),$(DESTDIR)/$(THEMESDIR),' \
22
ascd/Imakefile
23
sed -i -e 's,read CDD,CDD="",;t' \
24
ascd/configure
25
sed -i -e 's,read BINDIR,BINDIR="/usr/bin",;t' \
26
ascd/configure
27
sed -i -e 's,read MANDIR,MANDIR="/usr/share/man/man1",;t' \
28
ascd/configure
29
sed -i -e 's,read THDIR,THDIR="/usr/share/AScd",;t' \
30
ascd/configure
31
sed -i -e 's,read WINGS,WINGS="2",;t' \
32
ascd/configure
33
./configure
34
}
35
36
build() {
37
cd ${pkgname}-${pkgver}+lib-src
38
make CCOPTIONS="-fPIC" EXTRA_INCLUDES="-I."
39
}
40
41
package() {
42
cd ${pkgname}-${pkgver}+lib-src
43
make DESTDIR="$pkgdir" install install.man
44
cd libworkman
45
make LIBDIR="/usr/lib" DESTDIR="$pkgdir" install
46
chown -R root.root "$pkgdir/usr/share/AScd"
47
}
48
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |