avr-libc-atmega328pb

maintainer ctag · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads a data file (atpack) from a non-whitelisted but plausibly official Atmel host for hardware definitions, which is not executable and used only for building; the main avr-libc source is from a trusted GNU release mirror and PGP-verified.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a data file (atpack) from a non-whitelisted but plausibly official Atmel host for hardware definitions, which is not executable and used only for building; the main avr-libc source is from a trusted GNU release mirror and PGP-verified.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:28 source=("Atmel.ATmega_DFP.${pkgver}.zip::http://packs.download.atmel.com/Atmel.ATmega_DFP.${pkgver}.atpack"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: ctag <bigbero@gmail.com>
2
3# https://github.com/archlinux/svntogit-community/blob/packages/avr-libc/trunk/PKGBUILD
4# https://www.avrfreaks.net/comment/2526416#comment-2526416
5# https://github.com/Optiboot/optiboot/pull/297
6
7pkgname=avr-libc-atmega328pb
8pkgver=1.5.362
9pkgrel=3
10epoch=0
11_avrlibcver=2.0.0
12pkgdesc="The C runtime library for the AVR family of microcontrollers with Atmega328pb support"
13arch=('any')
14url="http://packs.download.atmel.com"
15license=('Apache')
16groups=()
17depends=(avr-gcc)
18makedepends=()
19checkdepends=()
20optdepends=()
21provides=('avr-libc')
22conflicts=('avr-libc')
23replaces=()
24backup=()
25options=(!strip)
26install=
27changelog=
28source=("Atmel.ATmega_DFP.${pkgver}.zip::http://packs.download.atmel.com/Atmel.ATmega_DFP.${pkgver}.atpack"
29 "io.h.patch"
30 https://download.savannah.gnu.org/releases/avr-libc/avr-libc-$_avrlibcver.tar.bz2{,.sig})
31noextract=()
32md5sums=('31f644ae9287a6ce9abd5e724f3d4661'
33 '55c28e5b0f5f55babd1a7a78afb571ab'
34 '2360981cd5d94e1d7a70dfc6983bdf15'
35 'SKIP')
36validpgpkeys=('5E84F980C3CAFD4BB5841070F48CA81B69A85873') # Joerg Wunsch
37
38prepare() {
39 cd "${srcdir}/avr-libc-${_avrlibcver}/include/avr"
40 patch -i "${srcdir}/io.h.patch"
41}
42
43build() {
44 cd avr-libc-$_avrlibcver
45 ./bootstrap
46 ./configure --build=$(./config.guess) --host=avr --prefix=/usr
47 make
48}
49
50package() {
51 install -D "${srcdir}/include/avr/iom328pb.h" -t "${pkgdir}/usr/avr/include/avr/"
52 install -D "${srcdir}/gcc/dev/atmega328pb/avr5/crtatmega328pb.o" -t "${pkgdir}/usr/avr/lib/avr5/"
53 install -D "${srcdir}/gcc/dev/atmega328pb/avr5/libatmega328pb.a" -t "${pkgdir}/usr/avr/lib/avr5/"
54
55 cd avr-libc-$_avrlibcver
56 make DESTDIR="$pkgdir" install
57
58 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/avr-libc/LICENSE"
59}
60

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion