docker-credential-atcr-git
Builds from source via git clone of a non-standard forge (tangled.org), but this appears to be the project's own repository; the PKGBUILD compiles Go code normally with no obfuscation, exfiltration, or remote code execution beyond building the project itself. The non-whitelisted host and few votes are minor concerns but not indicative of malice.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Builds from source via git clone of a non-standard forge (tangled.org), but this appears to be the project's own repository; the PKGBUILD compiles Go code normally with no obfuscation, exfiltration, or remote code execution beyond building the project itself. The non-whitelisted host and few votes are minor concerns but not indicative of malice.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
source=("$pkgname::git+https://tangled.org/did:plc:pddp4xt5lgnv2qsegbzzs4xg/at-container-registry.git")
PKGBUILD
1 offending line(s) highlighted# Maintainer: yuna0x0 <yuna@yuna0x0.com>
pkgname=docker-credential-atcr-git
pkgver=0.1.4.r46.g5aa13ab
pkgrel=1
pkgdesc="Docker credential helper for ATCR (AT Container Registry)"
arch=('x86_64' 'aarch64')
url="https://atcr.io"
license=('MIT')
depends=('glibc')
makedepends=('git' 'go')
provides=("docker-credential-atcr=$pkgver-$pkgrel")
conflicts=('docker-credential-atcr')
options=('!debug')
source=("$pkgname::git+https://tangled.org/did:plc:pddp4xt5lgnv2qsegbzzs4xg/at-container-registry.git")
sha256sums=('SKIP')
pkgver() {
cd "$pkgname"
git describe --long --abbrev=7 | sed 's/^v//;s/\([^-]*-g\)/r\1/;s/-/./g'
}
prepare() {
cd "$pkgname"
# On main the helper is a separate module that imports atcr.io/pkg/credhelper,
# so it only builds in workspace mode. Drop the scanner, deploy and seamark
# modules upstream's go.work also lists.
rm -f go.work go.work.sum
go work init . ./cmd/credential-helper/atcr
mkdir -p build
}
build() {
cd "$pkgname"
export CGO_CPPFLAGS="${CPPFLAGS}"
export CGO_CFLAGS="${CFLAGS}"
export CGO_CXXFLAGS="${CXXFLAGS}"
export CGO_LDFLAGS="${LDFLAGS}"
export GOPATH="${srcdir}"
export GOFLAGS="-buildmode=pie -trimpath -ldflags=-linkmode=external -mod=readonly -modcacherw"
# -ldflags here replaces the one from GOFLAGS, so repeat -linkmode=external.
go build -o build/docker-credential-atcr \
-ldflags "-linkmode=external \
-X main.version=$pkgver \
-X main.commit=$(git rev-parse HEAD) \
-X main.date=$(date -u -d "@$SOURCE_DATE_EPOCH" +%Y-%m-%d)" \
./cmd/credential-helper/atcr
}
check() {
cd "$pkgname"
export GOPATH="${srcdir}"
export GOFLAGS="-buildmode=pie -trimpath -ldflags=-linkmode=external -mod=readonly -modcacherw"
go test ./pkg/credhelper/... ./cmd/credential-helper/atcr/...
}
package() {
cd "$pkgname"
install -Dm755 build/docker-credential-atcr "$pkgdir/usr/bin/docker-credential-atcr"
install -Dm644 license "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
install -Dm644 INSTALLATION.md "$pkgdir/usr/share/doc/$pkgname/INSTALLATION.md"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |