fastdnaml

maintainer malacology · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is downloaded from the original project's official academic website, which is plausibly the project's own infrastructure, and the package builds from source without executing unreviewed remote code.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the original project's official academic website, which is plausibly the project's own infrastructure, and the package builds from source without executing unreviewed remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source=("${pkgname}-${pkgver}.tgz::https://www.life.illinois.edu/gary/programs/${_pkg}/${_pkg}_$pkgver.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Guoyi Zhang <myname at malacology dot net>
2
3pkgname=fastdnaml
4_pkg=fastDNAml
5pkgver=1.2.2
6pkgrel=0
7arch=('x86_64')
8pkgdesc="A tool for construction of phylogenetic trees of DNA sequences \
9 using maximum likelihood \
10 https://doi.org/10.1093/bioinformatics/10.1.41"
11url='https://www.life.illinois.edu/gary/programs/fastDNAml.html'
12license=('GPL-2.0-only')
13depends=('glibc' 'bash')
14makedepends=('gcc' 'make')
15source=("${pkgname}-${pkgver}.tgz::https://www.life.illinois.edu/gary/programs/${_pkg}/${_pkg}_$pkgver.tar.gz")
16sha1sums=('78197cbd760163f65085ac80c36d4286a1f29e34')
17
18build() {
19 cd $srcdir/${_pkg}_$pkgver/source
20 make
21}
22
23package() {
24 # binary
25 cd $srcdir/${_pkg}_$pkgver/source
26 install -Dm 755 $_pkg $pkgdir/usr/bin/$_pkg
27 # scripts
28 cd $srcdir/${_pkg}_$pkgver/scripts
29 for sh in $(ls *)
30do
31 install -Dm 644 $sh $pkgdir/usr/share/$pkgname/$sh
32done
33 # docs
34 cd $srcdir/${_pkg}_$pkgver/docs
35 for txt in $(ls *.txt)
36do
37 install -Dm 644 $txt $pkgdir/usr/share/doc/$pkgname/$txt
38done
39}
40

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion