ethq

MEDIUM
maintainer k0ste 2 votes scanned 2026-10-05 23:40:58.404909
View on AUR
Why flagged

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("${pkgname}-${pkgver}.tar.gz::https://codeload.${_uri}/tar.gz/refs/tags/v${_gitver}")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Shalygin Konstantin <k0ste@k0ste.ru>
2# Contributor: Shalygin Konstantin <k0ste@k0ste.ru>
3
4pkgname='ethq'
5pkgver='0.7.0'
6_gitver='0_7_0'
7pkgrel='2'
8pkgdesc='Ethernet NIC Queue stats viewer'
9arch=('x86_64' 'aarch64')
10_uri="github.com/isc-projects/${pkgname}"
11url="https://${_uri}"
12license=('MPL')
13depends=('ncurses')
14source=("${pkgname}-${pkgver}.tar.gz::https://codeload.${_uri}/tar.gz/refs/tags/v${_gitver}")
15sha256sums=('6e40d98d32abbe0915a7a8996edcdbae61a54bb1f34f2f8a5c9c8d3d2962ec23')
16
17prepare() {
18 # Remove hardcoded flags
19 sed --in-place \
20 --expression '/= -s/d' \
21 --expression '/= -O3/d' \
22 "${pkgname}-${_gitver}/Makefile"
23}
24
25build() {
26 cd "${pkgname}-${_gitver}"
27 CFLAGS="${CFLAGS} ${DEBUG_CFLAGS}" \
28 CXXLAGS="${CXXFLAGS} ${DEBUG_CXXFLAGS}" \
29 LDFLAGS="${LDFLAGS}" \
30 make
31}
32
33package() {
34 cd "${pkgname}-${_gitver}"
35 install -Dm0755 "${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
36 install -Dm0644 "LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.txt"
37}
38

Changes since previous scan

--- PKGBUILD @ 2026-06-18 16:11
+++ PKGBUILD @ 2026-10-05 23:40
@@ -4,17 +4,29 @@
pkgname='ethq'
pkgver='0.7.0'
_gitver='0_7_0'
-pkgrel='1'
+pkgrel='2'
pkgdesc='Ethernet NIC Queue stats viewer'
arch=('x86_64' 'aarch64')
-url="https://github.com/isc-projects/${pkgname}"
+_uri="github.com/isc-projects/${pkgname}"
+url="https://${_uri}"
license=('MPL')
depends=('ncurses')
-source=("${url}/archive/refs/tags/v${_gitver}.tar.gz")
-md5sums=('3fcfb62bf5c9ae2afac451574bb811ce')
+source=("${pkgname}-${pkgver}.tar.gz::https://codeload.${_uri}/tar.gz/refs/tags/v${_gitver}")
+sha256sums=('6e40d98d32abbe0915a7a8996edcdbae61a54bb1f34f2f8a5c9c8d3d2962ec23')
+
+prepare() {
+ # Remove hardcoded flags
+ sed --in-place \
+ --expression '/= -s/d' \
+ --expression '/= -O3/d' \
+ "${pkgname}-${_gitver}/Makefile"
+}
build() {
cd "${pkgname}-${_gitver}"
+ CFLAGS="${CFLAGS} ${DEBUG_CFLAGS}" \
+ CXXLAGS="${CXXFLAGS} ${DEBUG_CXXFLAGS}" \
+ LDFLAGS="${LDFLAGS}" \
make
}

Scan history

Scanned at (UTC)SeverityRules
2026-10-05 23:40:58 Medium 1
2026-06-18 16:11:54 Clean 0

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion