eudic
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=("${pkgname}-${pkgver}.deb::https://static.frdic.com/pkg/${pkgname}.deb?v=${_date}")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt proprietary binary .deb from static.frdic.com, which is the vendor's own CDN for Eudic (欧路词典), a well-known Chinese dictionary application. The host is not an official Linux distribution mirror but is the upstream vendor's own distribution point, similar to how many proprietary Linux apps distribute .deb files from their own CDN. The sha512sum is pinned, which mitigates substitution risk. However, the binary is executed directly (linked into /usr/bin), and the source is a prebuilt closed-source binary from a non-standard host with no reproducibility guarantees. This is a standard medium-risk pattern for proprietary AUR packages: not clearly malicious, but a supply-chain concern if the CDN is compromised or the binary contains undisclosed functionality. The DLAGENTS override with a custom User-Agent is a minor oddity but explained in the comment (server returns 404 for curl's default UA). Overall this fits the medium category for prebuilt binary from a vendor CDN, not high since the sha512 is pinned and the host is the legitimate vendor's own infrastructure.
PKGBUILD
1 offending line(s) highlighted# Maintainer: yjun <jerrysteve1101 at gmail dot com>
# Maintainer: sukanka <su975853527 at gmail dot com>
pkgname=eudic
pkgver=13.5.2
_date=2024-03-01
_lang=en
_flang=English
pkgrel=1
pkgdesc="Proprietary ${_flang} dictionary software for linux"
arch=('x86_64')
url="https://www.eudic.net/v4/${_lang}/app/${pkgname}"
license=('unknown')
depends=(
'hicolor-icon-theme'
# 'qt5-speech'
# 'qt5-webkit'
)
source=("${pkgname}-${pkgver}.deb::https://static.frdic.com/pkg/${pkgname}.deb?v=${_date}")
options=('!strip')
sha512sums=('941f1b3984b9789162107ed2548fc6f1de2690605b699e87053b912502619348844c35991ca8f6f6c60de8b6176699529a27e37455adcbe2d45bca03be78f3b3')
# sometime use curl to download source deb, throws 404 not found.
# user other UA instead of origion one fixed it.
# https://wiki.archlinux.org/index.php/Nonfree_applications_package_guidelines#Custom_DLAGENTS
DLAGENTS=("https::/usr/bin/curl -A 'Mozilla' -fLC - --retry 3 --retry-delay 3 -o %o %u")
prepare() {
mkdir -p build
tar -xf data.tar.xz -C build
}
package() {
_dirname=eusoft-${pkgname}
install -dm755 ${pkgdir}/usr/share
cp -pvr build/usr/share/* ${pkgdir}/usr/share/
# link executable
install -dm755 ${pkgdir}/usr/bin/
ln -s /usr/share/${_dirname}/${pkgname} \
${pkgdir}/usr/bin/${pkgname}
# desktop entry
sed -i "s|/usr/share/${_dirname}/AppRun|${pkgname}|g" \
${pkgdir}/usr/share/applications/eusoft-${pkgname}.desktop
sed -i 's|Name=欧路词典|Name=eudic\nName[zh_CN]=欧路词典|g' ${pkgdir}/usr/share/applications/eusoft-${pkgname}.desktop
# qt plugin path
# sed -i '4c Prefix = /usr/lib/qt/' \
# ${pkgdir}/usr/share/${_dirname}/qt.conf
# remove unused files.
rm -rf ${pkgdir}/usr/share/${_dirname}/{gstreamer-1.0,AppRun,lib*so*}
}
# vim: ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |