dispatch_ng

maintainer marsoft · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from a non-whitelisted host (Bintray), but it is the official release of the project hosted by the developer, building from source is standard for AUR, and the checksum is provided, making it low risk despite the non-standard host.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from a non-whitelisted host (Bintray), but it is the official release of the project hosted by the developer, building from source is standard for AUR, and the checksum is provided, making it low risk despite the non-standard host.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:22 source=(${pkgname}-${pkgver}.tar.gz::https://bintray.com/akashrawal/${pkgname}/download_file?file_path=release-1.0%2F${pkgname}-${pkgver}.tar.gz)

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Semyon Maryasin <simeon@maryasin.name>
2pkgname=dispatch_ng
3pkgver=1.0
4pkgrel=1
5epoch=
6pkgdesc="Load balancing software to speed up internet connection"
7arch=(x86_64 armv7h)
8url="https://gitlab.com/akash_rawal/dispatch_ng/"
9license=('GPL3')
10groups=()
11depends=(libevent)
12makedepends=()
13checkdepends=()
14optdepends=()
15provides=()
16conflicts=()
17replaces=()
18backup=()
19options=()
20install=
21changelog=
22source=(${pkgname}-${pkgver}.tar.gz::https://bintray.com/akashrawal/${pkgname}/download_file?file_path=release-1.0%2F${pkgname}-${pkgver}.tar.gz)
23noextract=()
24md5sums=('8020b78637075981fd73d09c4c3a081f')
25
26prepare() {
27 cd "$srcdir/${pkgname}-$pkgver"
28 #patch -p1 -i "$srcdir/$pkgname-$pkgver.patch"
29}
30
31build() {
32 cd "$srcdir/${pkgname}-$pkgver"
33 libtoolize
34 aclocal
35 automake --add-missing
36 autoconf
37 mkdir -p build
38 cd build
39 ../configure --prefix=/usr
40 make
41}
42
43check() {
44 cd "$srcdir/${pkgname}-$pkgver"
45 cd build
46 make -k check
47}
48
49package() {
50 cd "$srcdir/${pkgname}-$pkgver"
51 cd build
52 make DESTDIR="$pkgdir/" install
53 install -Dm 644 ../README.md "$pkgdir/usr/share/doc/${pkgname}/README.md"
54}
55

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion