asterisk-lts-22

maintainer ectospasm · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source URL is from downloads.asterisk.org, which is a legitimate and official project domain for Asterisk, making the download trustworthy despite not being on a standard whitelist; the package builds from official source code and does not execute untrusted binaries or scripts.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source URL is from downloads.asterisk.org, which is a legitimate and official project domain for Asterisk, making the download trustworthy despite not being on a standard whitelist; the package builds from official source code and does not execute untrusted binaries or scripts.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:150 source=("https://downloads.asterisk.org/pub/telephony/${_pkg}/releases/$_archive.tar.gz"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Trey Blancher $(base64 -d <<< dHJleUBibGFuY2hlci5uZXQK)
2# Contributor: Nigel Kukard <nkukard@lbsd.net>
3# Contributor: Caleb Maclennan <caleb@alerque.com>
4# Contributor: Maxim Kurnosenko <asusx2@mail.ru>
5# Contributor: Xavier Devlamynck <magicrhesus@ouranos.be>
6# Contributor: Alessio Biancalana <dottorblaster@gmail.com>
7# Contributor: Maik Broemme <mbroemme@libmpq.org>
8# Contributor: Denis 'GNUtoo' Carikli <GNUtoo@cyberdimension.org>
9
10pkgname=asterisk-lts-22
11_pkg=${pkgname/-lts-22/}
12pkgver=22.10.0
13pkgrel=1
14pkgdesc='A complete PBX solution - LTS Release 22'
15arch=(x86_64 i686 aarch64 armv7h)
16url=https://www.asterisk.org
17license=("GPL-2.0-only")
18provides=("${_pkg}")
19conflicts=("${_pkg}>22")
20replaces=("${_pkg}")
21depends=(alsa-lib
22 curl
23 jansson
24 libedit
25 libvorbis
26 libxml2
27 libxslt
28 opus
29 popt
30 speex)
31makedepends=(gsm
32 sqlite3)
33optdepends=(dahdi
34 gsm
35 libpri
36 libsrtp
37 libss7
38 lua51
39 openr2
40 postgresql
41 unixodbc)
42_confs=(acl.conf
43 adsi.conf
44 aeap.conf
45 agents.conf
46 alarmreceiver.conf
47 amd.conf
48 app_skel.conf
49 ari.conf
50 ast_debug_tools.conf
51 asterisk.adsi
52 asterisk.conf
53 calendar.conf
54 ccss.conf
55 cdr.conf
56 cdr_adaptive_odbc.conf
57 cdr_beanstalkd.conf
58 cdr_custom.conf
59 cdr_manager.conf
60 cdr_odbc.conf
61 cdr_pgsql.conf
62 cdr_sqlite3_custom.conf
63 cdr_tds.conf
64 cel.conf
65 cel_beanstalkd.conf
66 cel_custom.conf
67 cel_odbc.conf
68 cel_pgsql.conf
69 cel_sqlite3_custom.conf
70 cel_tds.conf
71 chan_dahdi.conf
72 chan_mobile.conf
73 chan_websocket.conf
74 cli.conf
75 cli_aliases.conf
76 cli_permissions.conf
77 codecs.conf
78 confbridge.conf
79 config_test.conf
80 console.conf
81 dbsep.conf
82 dnsmgr.conf
83 dsp.conf
84 dundi.conf
85 enum.conf
86 extconfig.conf
87 extensions.ael
88 extensions.conf
89 extensions.lua
90 extensions_minivm.conf
91 features.conf
92 festival.conf
93 followme.conf
94 func_odbc.conf
95 geolocation.conf
96 hep.conf
97 http.conf
98 iax.conf
99 iaxprov.conf
100 indications.conf
101 logger.conf
102 manager.conf
103 meetme.conf
104 minivm.conf
105 modules.conf
106 motif.conf
107 musiconhold.conf
108 ooh323.conf
109 phoneprov.conf
110 pjproject.conf
111 pjsip.conf
112 pjsip_notify.conf
113 pjsip_wizard.conf
114 prometheus.conf
115 queuerules.conf
116 queues.conf
117 res_config_mysql.conf
118 res_config_sqlite3.conf
119 res_config_odbc.conf
120 res_corosync.conf
121 res_curl.conf
122 res_fax.conf
123 res_http_media_cache.conf
124 res_ldap.conf
125 res_odbc.conf
126 res_parking.conf
127 res_pgsql.conf
128 res_snmp.conf
129 res_stun_monitor.conf
130 resolver_unbound.conf
131 rtp.conf
132 say.conf
133 sla.conf
134 smdi.conf
135 sorcery.conf
136 ss7.timers
137 stasis.conf
138 statsd.conf
139 stir_shaken.conf
140 telcordia-1.adsi
141 test_sorcery.conf
142 udptl.conf
143 unistim.conf
144 users.conf
145 voicemail.conf
146 websocket_client.conf
147 xmpp.conf)
148backup=("${_confs[@]/#/etc/${_pkg}/}")
149_archive="${_pkg}-$pkgver"
150source=("https://downloads.asterisk.org/pub/telephony/${_pkg}/releases/$_archive.tar.gz"
151 "${_pkg}.sysusers"
152 "${_pkg}.logrotated"
153 "${_pkg}.tmpfiles"
154 "fix-upnp.patch")
155sha256sums=('27e49d483efb0739faf7d0a17a9e55f88439347ed9668f24eea909440473c32e'
156 '38a53911647fb2308482179cba605ebf12345df37eed23eb4ea67bf0bf041486'
157 'b97dc10a262621c95e4b75e024834712efd58561267b59b9171c959ecd9f7164'
158 '1b6b489d4f71015bfc56ce739d92df7e9abdb349aed6f5a47dd9c18d84546c1b'
159 '55798baa02698de3d81c4b6e11097b3dee73b20e9dfa1e08091a7037830ad6d8')
160
161prepare() {
162 cd "$_archive"
163
164 local filename
165 for filename in "${source[@]}"; do
166 if [[ "$filename" =~ \.patch$ ]]; then
167 echo "Applying patch ${filename##*/}"
168 patch -p1 -N -i "$srcdir/${filename##*/}"
169 fi
170 done
171}
172
173build() {
174 cd "$_archive"
175
176 ./configure \
177 --prefix=/usr \
178 --sysconfdir=/etc \
179 --localstatedir=/var \
180 --sbindir=/usr/bin
181
182 make MENUSELECT_CFLAGS= OPTIMIZE= DEBUG= ASTVARRUNDIR="/run/${_pkg}" NOISY_BUILD=1
183}
184
185package(){
186 cd "$_archive"
187
188 make DESTDIR="$pkgdir" install
189 make DESTDIR="$pkgdir" install-headers
190 make DESTDIR="$pkgdir" samples
191
192 # Backup file list changes frequently and is hard to keep up to date. Check
193 # that our current meta data matches whatever just got packaged, else flunk
194 # with a helpful output of where the lists differ. We have to compare twice
195 # because cmp has a useful exit code, comm has a useful output, neither both
196 local _backs=($(cd "$pkgdir/etc/${_pkg}" && echo *))
197 cmp -s \
198 <(IFS=$'\n'; echo "${_confs[*]}" | sort) \
199 <(IFS=$'\n'; echo "${_backs[*]}" | sort) ||
200 (comm -3 --nocheck-order \
201 <(IFS=$'\n'; echo "${_confs[*]}" | sort) \
202 <(IFS=$'\n'; echo "${_backs[*]}" | sort) &&
203 exit 1)
204
205 sed -i -e 's,/var/run,/run,' "$pkgdir/etc/${_pkg}/asterisk.conf"
206 install -Dm644 -t "$pkgdir/usr/share/doc/${_pkg}/examples" "$pkgdir/etc/${_pkg}/"*
207
208 mv "$pkgdir/var/run" "$pkgdir"
209
210 pushd contrib/systemd
211 install -Dm644 -t "$pkgdir/usr/lib/systemd/system/" "$pkname"*.{service,socket}
212
213 pushd "$srcdir"
214 install -Dm644 "${_pkg}.sysusers" "$pkgdir/usr/lib/sysusers.d/${_pkg}.conf"
215 install -Dm644 "${_pkg}.logrotated" "$pkgdir/etc/logrotate.d/${_pkg}"
216 install -Dm644 "${_pkg}.tmpfiles" "$pkgdir/usr/lib/tmpfiles.d/${_pkg}.conf"
217
218 chmod 0750 "$pkgdir"/{etc,run,var/{lib,log,spool}}/"${_pkg}"
219}
220

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion