factorio-headless-experimental
The package downloads the official Factorio headless server binary from the project's own domain (factorio.com), which is a legitimate source; the non-whitelisted host is the project's official site, so the download is expected and not inherently risky.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads the official Factorio headless server binary from the project's own domain (factorio.com), which is a legitimate source; the non-whitelisted host is the project's official site, so the download is expected and not inherently risky.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:26
factorio_headless_x64_${pkgver}.tar.xz::http://www.factorio.com/get-download/${pkgver}/headless/linux64
PKGBUILD
1 offending line(s) highlighted# Maintainer: mickael9 <mickael9@gmail.com>
# Contributor: Sebastien Duthil <duthils@free.fr>
# Inspiration for service and config files: https://github.com/Bisa/factorio-init
pkgname=factorio-headless-experimental
pkgver=2.1.20
pkgrel=1
pkgdesc="A 2D game about building and maintaining factories - Server version (experimental branch)"
arch=('x86_64')
url="http://www.factorio.com/"
license=('custom: commercial')
conflicts=('factorio' 'factorio-demo' 'factorio-headless' 'factorio-experimental')
provides=("factorio-headless=$pkgver")
install=factorio-headless.install
options=(!strip)
backup=(etc/conf.d/factorio
etc/factorio/server-settings.json
etc/factorio/map-gen-settings.json
etc/factorio/map-settings.json
)
source=(LICENSE
factorio-headless.service
factorio-headless.conf
factorio-headless.sysusers
factorio_headless_x64_${pkgver}.tar.xz::http://www.factorio.com/get-download/${pkgver}/headless/linux64
)
sha256sums=('8859e0c8650bd90a7ff35f6ec15df91cbbc5ef6ffab6119876731feb811861d1'
'72bbef31fced163e5993eff0e73a836a557165775eb77e0d69b24fe5ec4690a7'
'53d148b3de26bcbe4af725ac34d7a607329aa9c4f87e00f8c2cb63154d8c1921'
'87dae15d1bcfb4683faea9c66498bd916bd27f8aa0dc724c4e21076dcf17da64'
'421a483dbcf69b76d854b7fdb86a800c94da04e414c20803c9fce82fc191bbb5')
# no modifications needed, the executable looks for:
# - data in /usr/share/factorio
# - config in ~/.factorio
package() {
install -Dm755 "${srcdir}/factorio/bin/x64/factorio" "${pkgdir}/usr/bin/factorio"
install -d "${pkgdir}/usr/share/factorio"
cp -r "${srcdir}/factorio/data"/* "${pkgdir}/usr/share/factorio"
install -Dm644 "${srcdir}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
install -Dm644 "${srcdir}/factorio-headless.sysusers" "${pkgdir}/usr/lib/sysusers.d/factorio.conf"
install -Dm644 "${srcdir}/factorio-headless.conf" "${pkgdir}/etc/conf.d/factorio"
install -Dm644 "${srcdir}/factorio-headless.service" "${pkgdir}/usr/lib/systemd/system/factorio.service"
# server-settings.json can contain sensitive data so we need to make it only readable by the factorio user
install -Dm600 "${srcdir}/factorio/data/server-settings.example.json" "${pkgdir}/etc/factorio/server-settings.json"
install -Dm644 "${srcdir}/factorio/data/map-gen-settings.example.json" "${pkgdir}/etc/factorio/map-gen-settings.json"
install -Dm644 "${srcdir}/factorio/data/map-settings.example.json" "${pkgdir}/etc/factorio/map-settings.json"
# public isn't really a good default especially with the default name/description
sed -i 's/^ "public": true/ "public": false/' "${pkgdir}/etc/factorio/server-settings.json"
}
Changes since previous scan
--- PKGBUILD @ 2026-09-22 00:15+++ PKGBUILD @ 2026-10-03 00:23@@ -3,7 +3,7 @@ # Inspiration for service and config files: https://github.com/Bisa/factorio-init pkgname=factorio-headless-experimental-pkgver=2.1.18+pkgver=2.1.20 pkgrel=1 pkgdesc="A 2D game about building and maintaining factories - Server version (experimental branch)" arch=('x86_64')@@ -30,7 +30,7 @@ '72bbef31fced163e5993eff0e73a836a557165775eb77e0d69b24fe5ec4690a7' '53d148b3de26bcbe4af725ac34d7a607329aa9c4f87e00f8c2cb63154d8c1921' '87dae15d1bcfb4683faea9c66498bd916bd27f8aa0dc724c4e21076dcf17da64'- '692f5f0b86b4f1259b695b88573662b9b9d7cba6d22b90be2c562da4a5c3de05')+ '421a483dbcf69b76d854b7fdb86a800c94da04e414c20803c9fce82fc191bbb5') # no modifications needed, the executable looks for:Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 13:37:53 | Medium | 1 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 17:23:26 | Medium | 1 |
| 2026-09-16 11:22:36 | Medium | 1 |