brother-mfc-j265w

maintainer beanaroo · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads official Brother printer driver RPMs from download.brother.com, which is the vendor's legitimate distribution domain; despite the static analyzer flag for a non-whitelisted host, the source is authentic and expected for this type of driver package, and the build process only extracts and relocates files without executing arbitrary remote code.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads official Brother printer driver RPMs from download.brother.com, which is the vendor's legitimate distribution domain; despite the static analyzer flag for a non-whitelisted host, the source is authentic and expected for this type of driver package, and the build process only extracts and relocates files without executing arbitrary remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 "http://download.brother.com/welcome/dlf006541/mfcj265wlpr-$pkgver-$pkgrel.i386.rpm"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Michael Heyns <beanaroo@gmail.com>
2# Copied from the MFC-J5910DW package created by Libernux <dutchman55@gmx.com>
3pkgname="brother-mfc-j265w"
4_model="j265w"
5pkgver="1.1.3"
6pkgrel=1
7pkgdesc="LPR and CUPS driver for the Brother MFC-J265W"
8arch=('i686' 'x86_64')
9url="http://solutions.brother.com/linux/en_us/"
10license=('custom:brother commercial license')
11depends=('cups')
12install="$pkgname.install"
13source=(
14 "http://download.brother.com/welcome/dlf006541/mfcj265wlpr-$pkgver-$pkgrel.i386.rpm"
15 "http://download.brother.com/welcome/dlf006543/mfcj265wcupswrapper-$pkgver-$pkgrel.i386.rpm"
16)
17md5sums=(
18 '0d6245511b601e7168cd811be812072c'
19 '418728947071aa087aa029ea24dc22da'
20)
21if test "$CARCH" == x86_64; then
22 depends+=('lib32-glibc')
23fi
24prepare() {
25# do not install in '/usr/local'
26 if [ -d $srcdir/usr/local/Brother ]; then
27 install -d $srcdir/usr/share
28 mv $srcdir/usr/local/Brother/ $srcdir/usr/share/brother
29 rm -rf $srcdir/usr/local
30 sed -i 's|/usr/local/Brother|/usr/share/brother|g' `grep -lr '/usr/local/Brother' ./`
31 fi
32# setup cups-directories
33 install -d $srcdir/usr/share/cups/model
34 install -d $srcdir/usr/lib/cups/filter
35# go to the cupswrapper directory and find the source file from which to generate a ppd- and wrapper-file
36 cd `find . -type d -name 'cupswrapper'`
37 if [ -f cupswrapper* ]; then
38 _wrapper_source=`ls cupswrapper*`
39 sed -i '/^\/etc\/init.d\/cups/d' $_wrapper_source
40 sed -i '/^sleep/d' $_wrapper_source
41 sed -i '/^lpadmin/d' $_wrapper_source
42 sed -i 's|/usr|$srcdir/usr|g' $_wrapper_source
43 sed -i 's|/opt|$srcdir/opt|g' $_wrapper_source
44 sed -i 's|/model/Brother|/model|g' $_wrapper_source
45 sed -i 's|lpinfo|echo|g' $_wrapper_source
46 export srcdir=$srcdir
47 ./$_wrapper_source
48 sed -i 's|$srcdir||' $srcdir/usr/lib/cups/filter/*lpdwrapper*
49 sed -i "s|$srcdir||" $srcdir/usr/lib/cups/filter/*lpdwrapper*
50 rm $_wrapper_source
51 fi
52# /etc/printcap is managed by cups
53 rm `find $srcdir -type f -name 'setupPrintcap*'`
54}
55package() {
56 cp -R $srcdir/usr $pkgdir
57 if [ -d $srcdir/opt ]; then cp -R $srcdir/opt $pkgdir; fi
58}
59

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion