docker-machine-driver-kvm2
maintainer zkhr6
· 19 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a prebuilt binary from Google Cloud Storage, which is a standard hosting provider for official Kubernetes project releases; while the host is not whitelisted, it is plausibly part of the project's official infrastructure, and the binary is installed directly without obfuscation or additional execution risks.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt binary from Google Cloud Storage, which is a standard hosting provider for official Kubernetes project releases; while the host is not whitelisted, it is plausibly part of the project's official infrastructure, and the binary is installed directly without obfuscation or additional execution risks.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=("${pkgname}-${pkgver}"::"https://storage.googleapis.com/minikube/releases/v${pkgver}/${pkgname}-${_goarch}")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Brittany Figueroa <dormwear underscore iure at crowley dot seership dot dev>
2
3
pkgname=docker-machine-driver-kvm2
4
pkgver=1.30.1
5
pkgrel=1
6
pkgdesc='Minikube-maintained KVM driver for docker-machine'
7
url='https://minikube.sigs.k8s.io'
8
license=('Apache')
9
arch=('x86_64')
10
_goarch='amd64'
11
depends=(
12
'dnsmasq'
13
'docker-machine'
14
'iptables-nft'
15
'libvirt'
16
'qemu'
17
)
18
optdepends=('docker: to manage containers in the machine')
19
source=("${pkgname}-${pkgver}"::"https://storage.googleapis.com/minikube/releases/v${pkgver}/${pkgname}-${_goarch}")
20
b2sums=('27a9e93981b85527973d4a0ea74d921e9501b395bc7138b54ab9d5ca9bc8bad9835b5e68c463d98e2766d714c7f89a96249d9b4b3bc8415a2097c44eda989f62')
21
22
package() {
23
install -D --mode 755 "${pkgname}-${pkgver}" "${pkgdir}/usr/bin/${pkgname}"
24
}
25
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |