clickhouse-common-static-bin

LOW
maintainer thebits 9 votes base clickhouse-bin scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads prebuilt ClickHouse binaries from the official vendor domain packages.clickhouse.com, which is plausibly the project's own release infrastructure; despite the static analyzer flag for a non-whitelisted host, this constitutes a standard and trusted source for official builds, not a supply-chain risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt ClickHouse binaries from the official vendor domain packages.clickhouse.com, which is plausibly the project's own release infrastructure; despite the static analyzer flag for a non-whitelisted host, this constitutes a standard and trusted source for official builds, not a supply-chain risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 "https://packages.clickhouse.com/tgz/$_channel/clickhouse-client-$pkgver-amd64.tgz"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Sergey Mezentsev <thebits@yandex.ru>
2pkgbase='clickhouse-bin'
3pkgname=('clickhouse-server-bin' 'clickhouse-common-static-bin' 'clickhouse-client-bin')
4# 'stable' - for production environment
5# 'testing' - most recent version
6# 'prestable' and 'lts' are available
7_channel='stable'
8pkgver=26.7.3.19
9pkgrel=1
10provides=('clickhouse')
11pkgdesc="ClickHouse is a fast open-source OLAP database management system"
12arch=('x86_64' 'aarch64')
13url="https://clickhouse.com/"
14license=('Apache-2.0')
15source_x86_64=(
16 "https://packages.clickhouse.com/tgz/$_channel/clickhouse-client-$pkgver-amd64.tgz"
17 "https://packages.clickhouse.com/tgz/$_channel/clickhouse-common-static-$pkgver-amd64.tgz"
18 "https://packages.clickhouse.com/tgz/$_channel/clickhouse-server-$pkgver-amd64.tgz"
19 "clickhouse.sysusers"
20 "clickhouse-server.service"
21)
22source_aarch64=(
23 "https://packages.clickhouse.com/tgz/$_channel/clickhouse-client-$pkgver-arm64.tgz"
24 "https://packages.clickhouse.com/tgz/$_channel/clickhouse-common-static-$pkgver-arm64.tgz"
25 "https://packages.clickhouse.com/tgz/$_channel/clickhouse-server-$pkgver-arm64.tgz"
26 "clickhouse.sysusers"
27 "clickhouse-server.service"
28)
29sha512sums_x86_64=('099e7a4e99976ed2e1aeed2dc3bf6082d10e9e52b351486e48bfb398d7cc73388f756d5925b454cda6b6b967f0b4136766d9c6b898d4453d2e54fb734368fe50'
30 'e6a30bb4acb9e2e063d2a99d93bf42f5bac12f92cba8993482d5b2f175eb1cca65ae4bbe02a1a1b5ac7c0a783886871b2c2abb6b26e601f72f0577697d3e9d4c'
31 'e2dc9b3f1f8acb1f394dde2aaa6bc9f8b1cef6081ed0a8fbf84ccae9a2f8f829ec7104751a658ba395de4c09496fbdaac9390f5348a69048cc800849bacb0931'
32 '70af4456ded1a1bb5cf29d2d3b29086aedc7875ef673e8817f389243f0c79eb491c9ce715b94542cbe16eb7489d97411ff0ab4a1a7f6c9b9120c659b87ea25b7'
33 '6b22c7e27961c1453f8ce71457085cb24271ed1962033f78ea2483560bb6ad265a117414c5a9627a1733429d4080adf1fea4490073a7e522a002753d4d87d01c')
34sha512sums_aarch64=('2f97bff5a39d4517f53a6586c9d90e71a97b93e9983c86d50602fc8d8cd25c312f40b96d9499db1592cc4ddd334ca638c256b51f410cb350aa6ed90a42dff793'
35 'e71192af6e45a7293a98dd0ab9de95eea4c63c21d03260b50ba73b57e124f50551d91f72bb4b2f8268a176e6252c9af28f489244492ebab21f0376529ae87f2f'
36 'ff817ebfeef18de68b9f5d118d9190df4be4199ecf1f8bc7c824a38fa6ea47bb8faf7c9e2ded0a5892e09d527a3a4736e3f737aa25961b869a7ec6e9ba142731'
37 '70af4456ded1a1bb5cf29d2d3b29086aedc7875ef673e8817f389243f0c79eb491c9ce715b94542cbe16eb7489d97411ff0ab4a1a7f6c9b9120c659b87ea25b7'
38 '6b22c7e27961c1453f8ce71457085cb24271ed1962033f78ea2483560bb6ad265a117414c5a9627a1733429d4080adf1fea4490073a7e522a002753d4d87d01c')
39
40
41package_clickhouse-client-bin() {
42 depends=('clickhouse-common-static-bin')
43 backup=('etc/clickhouse-client/config.xml')
44 pkgdesc="ClickHouse client and other client-related tools."
45
46 cd "clickhouse-client-$pkgver"
47 cp -a etc usr $pkgdir
48}
49
50package_clickhouse-common-static-bin() {
51 # options and directives overrides
52 pkgdesc="ClickHouse compiled binary files."
53
54 cd "clickhouse-common-static-$pkgver"
55 cp -a usr $pkgdir
56}
57
58package_clickhouse-server-bin() {
59 # options and directives overrides
60 pkgdesc="ClickHouse server and default configuration."
61 depends=('clickhouse-common-static-bin')
62 backup=(
63 'etc/clickhouse-server/config.xml'
64 'etc/clickhouse-server/users.xml'
65 )
66
67 cd "clickhouse-server-$pkgver"
68 cp -a usr "$pkgdir/"
69 cp -a lib "$pkgdir/usr"
70 mkdir -p "$pkgdir/etc/clickhouse-server"
71 cp -a etc/clickhouse-server "$pkgdir/etc"
72 install -D "$srcdir/clickhouse.sysusers" "${pkgdir}/usr/lib/sysusers.d/clickhouse.conf"
73 install -D "$srcdir/clickhouse-server.service" "${pkgdir}/usr/lib/systemd/system/clickhouse-server.service"
74}
75

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion