astah-professional
The package downloads a prebuilt .deb from the official vendor's CDN (change-vision.com), which is plausibly the project's own infrastructure; while the host is not whitelisted, the .deb is from the official vendor and contains only installable data, not an obfuscated payload or remote code execution.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt .deb from the official vendor's CDN (change-vision.com), which is plausibly the project's own infrastructure; while the host is not whitelisted, the .deb is from the official vendor and contains only installable data, not an obfuscated payload or remote code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=("https://cdn.change-vision.com/files/astah-professional_${pkgver}.${_pkgrel}-0_all.deb"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Julian Flake <flake_at_uni-koblenz_dot_de>
# Contributor: Sebastian Lau <lauseb644 _at_ gmail _dot_ com>
# Contributor: Caleb Cushing <xenoterracide@gmail.com>
# Contributor: Romain Schmitz <slopjong .at. slopjong .dot. de>
# Forked from Phillipe Smith <phillipe@archlinux.com.br>
pkgname='astah-professional'
_pkgname=${pkgname//-/_}
pkgver='10.1.0'
_pkgver=${pkgver//./_}
pkgrel=1
_pkgrel=9ceee1
pkgdesc='Full-Featured Software Modeling Tool for creating UML, ER Diagrams, DFD, Flowchart and more to create a clear understanding of your software design among teams.Easy-to-use UML2.x modeler'
arch=('any')
url="http://astah.net/products/astah-professional"
conflicts=('astah_community' 'astah-uml')
license=('custom')
depends=('jre21-openjdk')
source=("https://cdn.change-vision.com/files/astah-professional_${pkgver}.${_pkgrel}-0_all.deb"
"LICENSE"
"PRIVACY")
md5sums=('73fd8f692f3977d5721e9afc43a3f572'
'4667d0dfa5bde4924e3cea64fb310e94'
'd041a1336f18d00a99baa330b0e25fb9')
install="astah-professional.install"
package() {
msg2 "Extracting the data.tar.xz..."
bsdtar -xf $srcdir/data.tar.xz -C "$pkgdir/"
# rm -r ${pkgdir}/usr/share/doc
install -Dm644 $srcdir/LICENSE ${pkgdir}/usr/share/licenses/${_pkgname}/LICENSE || return 1
install -Dm644 $srcdir/PRIVACY ${pkgdir}/usr/share/licenses/${_pkgname}/PRIVACY || return 1
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |