chromap
maintainer fc-ibb105
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a compressed file hosted on a university-affiliated mirror (SUSTech), which is plausible for academic software distribution; the file is verified by a matching sha512sum, and chromap is built from its own source, which is normal AUR packaging practice despite the non-whitelisted host.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a compressed file hosted on a university-affiliated mirror (SUSTech), which is plausible for academic software distribution; the file is verified by a matching sha512sum, and chromap is built from its own source, which is normal AUR packaging practice despite the non-whitelisted host.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
"https://mirrors.sustech.edu.cn/git/fc-ibb105/aur/-/raw/main/$xz_name"
PKGBUILD
1 offending line(s) highlighted
1
pkgname=chromap
2
chromap_ver=0.3.2
3
pkgver=$chromap_ver
4
pkgrel=1
5
pkgdesc="An ultrafast method for aligning and preprocessing high throughput chromatin profiles. "
6
arch=('x86_64')
7
license=('custom:"Copyright (c) 2019 Haowen Zhang, Li Song, X. Shirley Liu, Heng Li"')
8
url="https://haowenz.github.io/chromap/"
9
depends=()
10
provides=("$pkgname")
11
conflicts=("$pkgname")
12
optdepends=()
13
14
file_name=${pkgname}-${pkgver}
15
xz_name=$file_name.xz
16
17
source=(
18
"https://mirrors.sustech.edu.cn/git/fc-ibb105/aur/-/raw/main/$xz_name"
19
)
20
21
chromap_sum=489706456caceb5ed23b854429efd82c9dc6517992b3c9075aaffcfc3e7e8f8beb6cad2d6c7e07839057861b02787549be9d02e884c8397686141a81f1c214e9
22
sha512sums=(
23
$chromap_sum
24
)
25
26
package() {
27
export LC_ALL=en_US.UTF-8
28
29
mkdir -p $pkgdir/usr/bin
30
#xz -d $xz_name
31
mv $file_name $pkgdir/usr/bin/$pkgname
32
chmod 755 $pkgdir/usr/bin/$pkgname
33
}
34
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |