eusoft-ting-es

LOW
maintainer Chapman 0 votes scanned 2026-10-09 02:12:05.690464
View on AUR
Why flagged

Downloads a prebuilt .deb from static.eudic.net, which is the official Eudic/Eusoft vendor domain matching the package's stated upstream URL (eudic.net), so this is an official release artifact with a pinned SHA256 checksum rather than an unverifiable third-party binary.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Downloads a prebuilt .deb from static.eudic.net, which is the official Eudic/Eusoft vendor domain matching the package's stated upstream URL (eudic.net), so this is an official release artifact with a pinned SHA256 checksum rather than an unverifiable third-party binary.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:36 "${pkgname}-${pkgver}.deb::https://static.eudic.net/pkg/ting_es/ting_es.deb"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Chapman <touch65536@gmail.com>
2
3pkgname=eusoft-ting-es
4pkgver=26.6.2
5pkgrel=1
6pkgdesc="Daily Spanish Listening (每日西语听力) for Linux (Community Repackage)"
7arch=('x86_64')
8url="https://www.eudic.net/v4/es/app/ting"
9license=('LicenseRef-Proprietary')
10provides=('ting-es' 'eusoft-ting-es')
11conflicts=('ting-es')
12depends=(
13 'alsa-lib'
14 'at-spi2-core'
15 'gtk3'
16 'hicolor-icon-theme'
17 'libnotify'
18 'libsecret'
19 'libxss'
20 'libxtst'
21 'nss'
22 'util-linux-libs'
23 'xdg-utils'
24)
25optdepends=(
26 'noto-fonts-cjk: Chinese font support'
27)
28options=(!strip !debug)
29
30source=(
31 "ting-es.sh"
32 "eusoft-ting-es.desktop"
33 "LICENSE"
34)
35source_x86_64=(
36 "${pkgname}-${pkgver}.deb::https://static.eudic.net/pkg/ting_es/ting_es.deb"
37)
38noextract=("${pkgname}-${pkgver}.deb")
39
40sha256sums=(
41 '480e44a9481a8f553c27e1ccfbf60457871515c5a8fcd1b778378ef8796457c4'
42 'aae129f7a07cceaedc8a7d6c4527b54a27a3b2f0aa3961a540a4d44b2a04f4a0'
43 'cf9ba50ac9a100c03be7e11953e99443a5e8d26ed2f4453ecc454113778b668c'
44)
45sha256sums_x86_64=(
46 'f60b760b359f1593aa3b143943af951003f5b042167af7b2fb3249aa5f4a7377'
47)
48
49prepare() {
50 bsdtar -xf "${pkgname}-${pkgver}.deb" data.tar.xz
51}
52
53package() {
54 # Extract opt and usr hierarchies from official deb data
55 tar -xf data.tar.xz -C "${pkgdir}"
56
57 # Install clean launcher script
58 install -Dm755 "${srcdir}/ting-es.sh" "${pkgdir}/usr/bin/ting-es"
59 ln -sf ting-es "${pkgdir}/usr/bin/${pkgname}"
60
61 # Install desktop entry
62 install -Dm644 "${srcdir}/eusoft-ting-es.desktop" "${pkgdir}/usr/share/applications/eusoft-ting-es.desktop"
63 ln -sf eusoft-ting-es.desktop "${pkgdir}/usr/share/applications/ting_es.desktop"
64
65 # Install license
66 install -Dm644 "${srcdir}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
67
68 # Ensure executable permissions for electron binary
69 chmod 755 "${pkgdir}/opt/每日西语听力/ting_es"
70
71 # Normalize directory permissions
72 find "${pkgdir}" -type d -exec chmod 755 {} +
73}
74

Scan history

Scanned at (UTC)SeverityRules
2026-10-09 02:12:05 Low 3
2026-10-09 02:10:17 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion