eusoft-ting-en

LOW
maintainer Chapman 0 votes scanned 2026-10-09 02:12:05.690464
View on AUR
Why flagged

Downloads a prebuilt .deb from static.eudic.net, which is the official vendor domain for Eudic/Eusoft products, with a pinned sha256 checksum; the only concern is that it is a proprietary prebuilt binary, but it comes from the project's own official infrastructure rather than an unrelated swappable host.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 75%): Downloads a prebuilt .deb from static.eudic.net, which is the official vendor domain for Eudic/Eusoft products, with a pinned sha256 checksum; the only concern is that it is a proprietary prebuilt binary, but it comes from the project's own official infrastructure rather than an unrelated swappable host.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:37 "${pkgname}-${pkgver}.deb::https://static.eudic.net/pkg/ting_en/ting_en.deb?v=${_source_ver}"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Chapman <touch65536@gmail.com>
2
3pkgname=eusoft-ting-en
4pkgver=26.6.2
5_source_ver=26.9.1
6pkgrel=1
7pkgdesc="Daily English Listening (每日英语听力) for Linux (Community Repackage)"
8arch=('x86_64')
9url="https://www.eudic.net/v4/en/app/ting"
10license=('LicenseRef-Proprietary')
11provides=('ting-en' 'eusoft-ting' 'eusoft-ting-en')
12conflicts=('ting-en')
13depends=(
14 'alsa-lib'
15 'at-spi2-core'
16 'gtk3'
17 'hicolor-icon-theme'
18 'libnotify'
19 'libsecret'
20 'libxss'
21 'libxtst'
22 'nss'
23 'util-linux-libs'
24 'xdg-utils'
25)
26optdepends=(
27 'noto-fonts-cjk: Chinese font support'
28)
29options=(!strip !debug)
30
31source=(
32 "ting-en.sh"
33 "eusoft-ting-en.desktop"
34 "LICENSE"
35)
36source_x86_64=(
37 "${pkgname}-${pkgver}.deb::https://static.eudic.net/pkg/ting_en/ting_en.deb?v=${_source_ver}"
38)
39noextract=("${pkgname}-${pkgver}.deb")
40
41sha256sums=(
42 'cb43dcf4fb84da5a129a1966f75c28ae90f0fd4420a7b0440f208aafe80df13f'
43 '2c9e526e8475c970ee9be671477946a5d98eeae89ed5c356f844c2058fd054da'
44 '377ddd4aecf677aa2b0fdd264f6285118f3e01f6463eb957db972d0b8404cf69'
45)
46sha256sums_x86_64=(
47 'f90beed26f9e6a834cb6055925d8d844c6290bb44a7da91d9d0b674da8b3cd5b'
48)
49
50prepare() {
51 bsdtar -xf "${pkgname}-${pkgver}.deb" data.tar.xz
52}
53
54package() {
55 # Extract opt and usr hierarchies from official deb data
56 tar -xf data.tar.xz -C "${pkgdir}"
57
58 # Install clean launcher script
59 install -Dm755 "${srcdir}/ting-en.sh" "${pkgdir}/usr/bin/ting-en"
60 ln -sf ting-en "${pkgdir}/usr/bin/ting"
61 ln -sf ting-en "${pkgdir}/usr/bin/${pkgname}"
62 ln -sf ting-en "${pkgdir}/usr/bin/eusoft-ting"
63
64 # Install desktop entry
65 install -Dm644 "${srcdir}/eusoft-ting-en.desktop" "${pkgdir}/usr/share/applications/eusoft-ting-en.desktop"
66 ln -sf eusoft-ting-en.desktop "${pkgdir}/usr/share/applications/ting_en.desktop"
67
68 # Install license
69 install -Dm644 "${srcdir}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
70
71 # Ensure executable permissions for electron binary
72 chmod 755 "${pkgdir}/opt/每日英语听力/ting_en"
73
74 # Normalize directory permissions
75 find "${pkgdir}" -type d -exec chmod 755 {} +
76}
77

Scan history

Scanned at (UTC)SeverityRules
2026-10-09 02:12:05 Low 3
2026-10-09 02:10:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion