auditbeat-oss-bin

LOW
maintainer thorko 0 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads a prebuilt binary from Elastic's official artifacts domain, which is the project's legitimate release infrastructure; despite the non-whitelisted host, this is a standard and expected source for the software, and no code execution or redirection occurs beyond normal installation.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt binary from Elastic's official artifacts domain, which is the project's legitimate release infrastructure; despite the non-whitelisted host, this is a standard and expected source for the software, and no code execution or redirection occurs beyond normal installation.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("https://artifacts.elastic.co/downloads/beats/auditbeat/auditbeat-${pkgver}-linux-x86_64.tar.gz"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Thorsten Müller
2
3pkgname=auditbeat-oss-bin
4pkgver=9.5.4
5pkgrel=0
6pkgdesc='Data shippers for Elasticsearch'
7arch=('x86_64')
8url='https://www.elastic.co/products/beats'
9license=('Apache')
10depends=('glibc')
11conflicts=(auditbeat-oss)
12source=("https://artifacts.elastic.co/downloads/beats/auditbeat/auditbeat-${pkgver}-linux-x86_64.tar.gz"
13 "auditbeat-oss.service")
14sha512sums=('89c3c5f541e571e0c6141cf711ecf81983b8136459052efe2f8b57a4a0d36ca62cecebe92e1f5cc112d2b5d739fdeec23be9603b08cfd0216967448d756e35c6'
15 '6c2b7ad706efbbaab55e2bd6a63dd85ee358aeed8255a829adeacdcd45d364520cc7f0328cfa966d61e911042d8fac40abc7ff36cdb7a834fc83df7da94fce13')
16backup=('etc/auditbeat-oss/auditbeat.yml', 'etc/auditbeat-oss/fields.yml')
17srcpath="auditbeat-${pkgver}-linux-x86_64"
18
19package() {
20 install -Dm755 "${srcdir}/${srcpath}/auditbeat" "${pkgdir}/usr/bin/auditbeat-oss"
21 install -Dm644 "${srcdir}/${srcpath}/auditbeat.yml" "${pkgdir}/etc/auditbeat-oss/auditbeat.yml"
22 install -Dm644 "${srcdir}/${srcpath}/auditbeat.reference.yml" "${pkgdir}/etc/auditbeat-oss/auditbeat.reference.yml"
23 install -Dm644 "${srcdir}/${srcpath}/fields.yml" "${pkgdir}/etc/auditbeat-oss/fields.yml"
24 install -Dm644 "auditbeat-oss.service" "${pkgdir}/usr/lib/systemd/system/auditbeat-oss.service"
25}
26

Changes since previous scan

--- PKGBUILD @ 2026-09-16 00:03
+++ PKGBUILD @ 2026-10-02 00:00
@@ -1,7 +1,7 @@
# Maintainer: Thorsten Müller
pkgname=auditbeat-oss-bin
-pkgver=9.5.3
+pkgver=9.5.4
pkgrel=0
pkgdesc='Data shippers for Elasticsearch'
arch=('x86_64')
@@ -11,7 +11,7 @@
conflicts=(auditbeat-oss)
source=("https://artifacts.elastic.co/downloads/beats/auditbeat/auditbeat-${pkgver}-linux-x86_64.tar.gz"
"auditbeat-oss.service")
-sha512sums=('a6be83aacc896012c376edaf75eefb0296e9b5cc11e42d36195f4f66d075bc9b9070216b9e729eac82214d3f4f79e1c4537539c9945817499d868041c4c5f3fb'
+sha512sums=('89c3c5f541e571e0c6141cf711ecf81983b8136459052efe2f8b57a4a0d36ca62cecebe92e1f5cc112d2b5d739fdeec23be9603b08cfd0216967448d756e35c6'
'6c2b7ad706efbbaab55e2bd6a63dd85ee358aeed8255a829adeacdcd45d364520cc7f0328cfa966d61e911042d8fac40abc7ff36cdb7a834fc83df7da94fce13')
backup=('etc/auditbeat-oss/auditbeat.yml', 'etc/auditbeat-oss/fields.yml')
srcpath="auditbeat-${pkgver}-linux-x86_64"

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 11:22:36 Medium 1
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion