clever-tools-bin
The package downloads a prebuilt binary from the project's own domain, which is plausibly official; while the host is not a standard forge, it is project-specific and the binary is used to generate shell completions, indicating intended functionality rather than obfuscated execution.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt binary from the project's own domain, which is plausibly official; while the host is not a standard forge, it is project-specific and the binary is used to generate shell completions, indicating intended functionality rather than obfuscated execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
source=("clever-tools-5.0.2_linux.tar.gz::https://clever-tools.clever-cloud.com/releases/5.0.2/clever-tools-5.0.2_linux.tar.gz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Clever Cloud <ci@clever-cloud.com>
pkgname=clever-tools-bin
pkgver=5.0.2
pkgrel=1
pkgdesc="Command Line Interface for Clever Cloud. (standalone binary)"
arch=('x86_64')
url="https://github.com/CleverCloud/clever-tools"
license=('Apache-2.0')
# The binary embeds Node.js but is still dynamically linked against the C and C++ runtimes
depends=('glibc' 'gcc-libs')
provides=('clever-tools')
conflicts=('clever-tools')
# Prebuilt binary: stripping it breaks it, and there are no debug symbols to extract
options=(!strip !debug)
source=("clever-tools-5.0.2_linux.tar.gz::https://clever-tools.clever-cloud.com/releases/5.0.2/clever-tools-5.0.2_linux.tar.gz")
sha256sums=('01fb1260bd9cdfe0e392e4e0494466f4e6a6e83907aec3c1f07757efd08cb3ed')
package() {
install -d "${pkgdir}/usr/bin"
install -d "${pkgdir}/usr/share/bash-completion/completions"
install -d "${pkgdir}/usr/share/zsh/site-functions"
install "${srcdir}/clever-tools-5.0.2_linux/clever" "${pkgdir}/usr/bin/clever"
"${srcdir}/clever-tools-5.0.2_linux/clever" --bash-autocomplete-script /usr/bin/clever > "${pkgdir}/usr/share/bash-completion/completions/clever"
"${srcdir}/clever-tools-5.0.2_linux/clever" --zsh-autocomplete-script /usr/bin/clever > "${pkgdir}/usr/share/zsh/site-functions/_clever"
}
Changes since previous scan
--- PKGBUILD @ 2026-09-16 00:03+++ PKGBUILD @ 2026-09-17 00:27@@ -1,7 +1,7 @@ # Maintainer: Clever Cloud <ci@clever-cloud.com> pkgname=clever-tools-bin-pkgver=5.0.1+pkgver=5.0.2 pkgrel=1 pkgdesc="Command Line Interface for Clever Cloud. (standalone binary)" arch=('x86_64')@@ -15,16 +15,16 @@ # Prebuilt binary: stripping it breaks it, and there are no debug symbols to extract options=(!strip !debug) -source=("clever-tools-5.0.1_linux.tar.gz::https://clever-tools.clever-cloud.com/releases/5.0.1/clever-tools-5.0.1_linux.tar.gz")-sha256sums=('31a9c59d5c2706762061eae359b17c7751c86c32142ee598a7e41a451db3531e')+source=("clever-tools-5.0.2_linux.tar.gz::https://clever-tools.clever-cloud.com/releases/5.0.2/clever-tools-5.0.2_linux.tar.gz")+sha256sums=('01fb1260bd9cdfe0e392e4e0494466f4e6a6e83907aec3c1f07757efd08cb3ed') package() { install -d "${pkgdir}/usr/bin" install -d "${pkgdir}/usr/share/bash-completion/completions" install -d "${pkgdir}/usr/share/zsh/site-functions" - install "${srcdir}/clever-tools-5.0.1_linux/clever" "${pkgdir}/usr/bin/clever"+ install "${srcdir}/clever-tools-5.0.2_linux/clever" "${pkgdir}/usr/bin/clever" - "${srcdir}/clever-tools-5.0.1_linux/clever" --bash-autocomplete-script /usr/bin/clever > "${pkgdir}/usr/share/bash-completion/completions/clever"- "${srcdir}/clever-tools-5.0.1_linux/clever" --zsh-autocomplete-script /usr/bin/clever > "${pkgdir}/usr/share/zsh/site-functions/_clever"+ "${srcdir}/clever-tools-5.0.2_linux/clever" --bash-autocomplete-script /usr/bin/clever > "${pkgdir}/usr/share/bash-completion/completions/clever"+ "${srcdir}/clever-tools-5.0.2_linux/clever" --zsh-autocomplete-script /usr/bin/clever > "${pkgdir}/usr/share/zsh/site-functions/_clever" }Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 15:22:50 | Medium | 1 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 11:16:56 | Medium | 1 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 11:22:29 | Medium | 1 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |