factorio-demo

maintainer bschnei · 10 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The download is from the official project domain (factorio.com) which is plausibly the project's own release infrastructure, making it a standard source for the software despite the non-whitelisted host; the package installs legitimate game files and runs no untrusted remote code.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The download is from the official project domain (factorio.com) which is plausibly the project's own release infrastructure, making it a standard source for the software despite the non-whitelisted host; the package installs legitimate game files and runs no untrusted remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=(factorio-demo_linux_${pkgver}.tar.xz::http://www.factorio.com/get-download/${pkgver}/demo/linux64

PKGBUILD

1 offending line(s) highlighted
1pkgname=factorio-demo
2pkgver=2.0.77
3pkgrel=1
4pkgdesc="A game in which you build and maintain factories"
5arch=(x86_64)
6url="http://www.factorio.com/"
7license=(LicenseRef-factorio)
8depends=(glibc)
9makedepends=(xz)
10conflicts=('factorio' 'factorio-headless' 'factorio-experimental')
11source=(factorio-demo_linux_${pkgver}.tar.xz::http://www.factorio.com/get-download/${pkgver}/demo/linux64
12 factorio.desktop
13 LICENSE
14)
15sha256sums=('f2fc889de1924b551cf52ca2ce2c73251f9c20ee2ae38cc8e973415baffef2a1'
16 '8b5d83c82c2b93b7765e6a51abca11dd53858a47a5bb5c5a36591b8dec9173a6'
17 '02b42f985d69541660200cd286642b3e9c9af070f95b95588910c9bf93044aa7')
18
19package() {
20 cd "${srcdir}"
21
22 install -Dm644 factorio.desktop -t "${pkgdir}/usr/share/applications/"
23 install -Dm644 LICENSE -t "${pkgdir}/usr/share/licenses/${pkgname}/"
24
25 cd factorio
26 install -Dm755 bin/x64/factorio -t "${pkgdir}/usr/bin/"
27
28 install -d "${pkgdir}/usr/share/factorio"
29 cp -r data/* "${pkgdir}/usr/share/factorio"
30}
31
32check() {
33 cd "${srcdir}/factorio"
34 ./bin/x64/factorio --version
35}
36

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion