busybox-alpinevariant-git
The package builds from the official busybox git repository and uses Alpine's configuration from a non-whitelisted but plausibly official source; both sources have SKIP'd checksums but no remote code execution or malicious behavior is present, and the build is otherwise standard for an AUR package.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds from the official busybox git repository and uses Alpine's configuration from a non-whitelisted but plausibly official source; both sources have SKIP'd checksums but no remote code execution or malicious behavior is present, and the build is otherwise standard for an AUR package.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("git+https://git.busybox.net/busybox" -
PKGBUILD:15
"config::https://git.alpinelinux.org/aports/plain/main/busybox/busyboxconfig")
PKGBUILD
2 offending line(s) highlighted# Maintainer: cuzrawr
# original PKGBUILD copied from Chocobo1 ( pkg busybox-git ) ( thanks )
pkgname=busybox-alpinevariant-git
pkgver=1.35.0.r133.g8d67007a4
pkgrel=1
pkgdesc="This variant of busybox primary focus on ash shell and optimized for everyday use as an light alternative to bash."
arch=('x86_64')
url="https://www.busybox.net/"
license=('GPL')
makedepends=('git' 'ncurses')
provides=('busybox-alpinevariant-git')
conflicts=("busybox" "busybox-custom" "busybox-custom-git" "mindi-busybox" "busybox-norootreboot" "busybox-git")
source=("git+https://git.busybox.net/busybox"
"config::https://git.alpinelinux.org/aports/plain/main/busybox/busyboxconfig")
sha256sums=('SKIP'
'SKIP')
install='busybox-alpinevariant-git.install'
pkgver() {
cd "busybox"
git describe --long --tags | sed 's/\([^-]*-g\)/r\1/;s/[_-]/./g'
}
build() {
cd "busybox"
# .config: ( check readme.md )
# cp "$srcdir/../config-example-latest" "$srcdir/busybox/.config"
#
# patch:
# This patch just removes line numbers in history command
# and making history output more readable and grepable.
cp "$srcdir/../show_history-patch.lineedit.c.patch" "$srcdir/busybox/lineedit.c.patch"
# For pure alpine busybox config uncoment this line:
cp "$srcdir/../config" "$srcdir/busybox/.config"
yes "" | make oldconfig
# Uncomment to make custom changes
#
#make menuconfig
# Apply fancy "show history output" patch
patch -p0 < lineedit.c.patch
export KCONFIG_NOTIMESTAMP=1 # reproducible build
make
}
check() {
cd "busybox"
#make check
}
package() {
cd "busybox"
install -Dm755 "busybox" -t "$pkgdir/usr/bin"
# uncomment next lines for installing docs and manpages:
#install -Dm644 "docs/busybox.1" -t "$pkgdir/usr/share/man/man1"
#install -Dm644 "docs"/BusyBox.{html,txt} -t "$pkgdir/usr/share/doc/busybox"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |