cosmocc-bin
maintainer tee
· 3 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a prebuilt toolchain from a project-specific domain (cosmo.zip) which, while not on a standard host, is plausibly official; the content is not obfuscated and is installed as a binary toolchain, a common use case, with a valid checksum, reducing risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt toolchain from a project-specific domain (cosmo.zip) which, while not on a standard host, is plausibly official; the content is not obfuscated and is installed as a binary toolchain, a common use case, with a valid checksum, reducing risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
"https://cosmo.zip/pub/cosmocc/cosmocc-$pkgver.zip"
PKGBUILD
1 offending line(s) highlighted
1
# Contributor: Asger Hautop Drewsen <asger@tyilo.com>
2
# Maintainer: tee < teeaur at duck dot com >
3
4
pkgname=cosmocc-bin
5
pkgver=4.0.2
6
pkgrel=1
7
pkgdesc="cosmopolitan toolchain: build-once run-anywhere c library"
8
arch=('x86_64' 'aarch64')
9
url="https://justine.lol/cosmopolitan/index.html"
10
license=('ISC')
11
depends=()
12
makedepends=()
13
options=('!strip')
14
source=(
15
"https://cosmo.zip/pub/cosmocc/cosmocc-$pkgver.zip"
16
"bin-wrapper"
17
)
18
noextract=(
19
"cosmocc-$pkgver.zip"
20
)
21
sha512sums=('e4361ed69528f47abc7336474871c5177734b88aebdf7b625b67554dd14fbe7be3d70409b12542c0cd3b48f7a17d54d340a09acffa7d024f1ea2073f429fab69'
22
'd2bb2bcf5eee88a16f78849fd42a63a65539611a030815a56b19b27a25d9abe0fe3a0a746a58c00a2e468b917d1689f5a0048ddfb73c351f5f71d0d0a7015271')
23
24
package() {
25
install -dm755 "$pkgdir/opt/cosmocc"
26
cd "$pkgdir/opt/cosmocc"
27
bsdtar -xf "$srcdir/cosmocc-$pkgver.zip"
28
chmod -R 755 "$pkgdir/opt"
29
30
install -dm755 "$pkgdir/usr/bin"
31
for bin in cosmo* aarch64-* x86_64-*; do
32
cp "$srcdir/bin-wrapper" "$pkgdir/usr/bin/$bin"
33
done
34
}
35
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |