dingoo-sdk
The package downloads source files from Google Code Archive, which is a non-standard host but hosts legitimate historical project releases; the files are verified by checksums and consist of SDK tools and scripts, not executable payloads, and the build process installs only these verified files without executing untrusted code.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads source files from Google Code Archive, which is a non-standard host but hosts legitimate historical project releases; the files are verified by checksums and consist of SDK tools and scripts, not executable payloads, and the build process installs only these verified files without executing untrusted code.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/dingoo-sdk/dingoo_sdk_r324.zip"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Peter Ivanov <ivanovp@gmail.com>
pkgname=dingoo-sdk
pkgver=20130707
pkgrel=3
pkgdesc="Dingoo A320 Native SDK"
arch=('i686' 'x86_64')
url="http://code.google.com/p/dingoo-sdk/"
license=('GPL')
depends=('bash' 'sed' 'python')
makedepends=('make')
options=(!strip)
install=dingoo-sdk.install
source=("https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/dingoo-sdk/dingoo_sdk_r324.zip"
"https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/dingoo-sdk/linux_x86_elf2app.tar.bz2"
"https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/dingoo-sdk/mipsel-4.1.2-nopic.tar.bz2"
"dingoo-sdk.sh")
#_gitroot="http://dingoo-sdk.googlecode.com/svn/trunk/ dingoo-sdk-read-only"
#_gitname=dingoo-sdk
build() {
cd "$srcdir"
# if [ -d "$_gitname" ]; then
# msg "GIT tree found."
# cd "$_gitname"
# git pull
# else
# git clone $_gitroot
# cd "$_gitname"
# fi
# qmake
# make
cd dingoo_sdk
export DINGOO_SDK=$srcdir/dingoo_sdk
export MIPSTOOLS=$srcdir/mipsel-4.1.2-nopic
export PATH=$PATH:$MIPSTOOLS/bin
sh ./install
# Removing unnecessary object files
find $DINGOO_SDK -iname '*.o' -and -not -name 'dingoo.o'|xargs rm -f
}
package() {
cd $srcdir
install -d -m755 $pkgdir/usr/bin
install -m755 dingoo-sdk.sh $pkgdir/usr/bin/dingoo-sdk.sh
install -d -m755 $pkgdir/usr/share/$pkgname
cp -a dingoo_sdk $pkgdir/usr/share/$pkgname
cp -a mipsel-4.1.2-nopic $pkgdir/usr/share/$pkgname
cp -a tools $pkgdir/usr/share/$pkgname
}
md5sums=('0ed152a9d947897b4e346e554b90fe39'
'6d617c4b6fbee77eeb84284f451d58ca'
'd980b89d5604a422f4a80d3c86b9a5fd'
'e84d16d30743c6b0b6ff76c060b681f6')
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |