ecity
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source=("http://ecity-project.eu/${pkgname}-${pkgver}-linux.zip"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads a prebuilt binary (a Unity-based Linux executable) from the project's own domain (ecity-project.eu), which is the official upstream URL matching the package's stated homepage. The binary is installed to /opt and executed at runtime. While the host is not a major distribution mirror, it is the official project website, not a personal or third-party host. The concern is real but modest: there is no checksum algorithm stronger than MD5 (weak integrity guarantee), and the binary is a closed prebuilt Unity application from a small academic project whose domain could be abandoned or compromised. This fits the medium category — a prebuilt executable from a small/unofficial host with only MD5 verification — but is not clearly malicious.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Ricardo Gonçalves <ricardompgoncalves@gmail.com>
pkgname=ecity
pkgver=1.5.1
pkgrel=1
pkgdesc="Virtual City Environment for Engineering Problem Based Learning"
arch=('i686' 'x86_64')
url="http://ecity-project.eu"
license=('GPL')
depends=()
source=("http://ecity-project.eu/${pkgname}-${pkgver}-linux.zip"
"${pkgname}.desktop")
md5sums=('140ba9db9ac7042a8312c9b449a40d5b'
'b22d47c4787a9e15e96c9fcf1b733848')
package() {
# Create directories
mkdir -pv "${pkgdir}/opt/${pkgname}"
mkdir -pv "${pkgdir}/usr/bin"
mkdir -pv "${pkgdir}/usr/share/applications/"
# Move files
cp "${pkgname}.desktop" "${pkgdir}/usr/share/applications/"
cp "${pkgname}-${pkgver}_Data/Resources/UnityPlayer.png" "${pkgdir}/opt/${pkgname}/${pkgname}.png"
mv "${pkgname}-${pkgver}_Data" "${pkgdir}/opt/${pkgname}/"
mv "${pkgname}-${pkgver}.x86" "${pkgdir}/opt/${pkgname}/"
# Create links
ln -sv "/opt/${pkgname}/${pkgname}-${pkgver}.x86" "${pkgdir}/opt/${pkgname}/${pkgname}"
echo \#\!/bin/sh > "${pkgdir}/opt/${pkgname}/${pkgname}.sh"
echo "/opt/${pkgname}/${pkgname}" >> "${pkgdir}/opt/${pkgname}/${pkgname}.sh"
chmod a+x "${pkgdir}/opt/${pkgname}/${pkgname}.sh"
ln -sv "/opt/${pkgname}/${pkgname}.sh" "${pkgdir}/usr/bin/${pkgname}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |