forge-server-patchouli

maintainer orphaned · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads a prebuilt JAR file from a non-whitelisted but official and plausible mod distribution host (forgecdn.net), which is commonly used for Minecraft mods; the file is installed as a mod without execution of remote code, and the license file is sourced from GitHub; while the host is not whitelisted, the context suggests legitimate use.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt JAR file from a non-whitelisted but official and plausible mod distribution host (forgecdn.net), which is commonly used for Minecraft mods; the file is installed as a mod without execution of remote code, and the license file is sourced from GitHub; while the host is not whitelisted, the context suggests legitimate use.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 https://mediafiles.forgecdn.net/files/3877/555/Patchouli-1.19-75.jar)

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Dominik Opyd <d.opyd@oad.earth>
2
3pkgname=forge-server-patchouli
4modname=patchouli
5srvname=forge
6pkgver=0.0.75
7minver=1.19
8pkgrel=1
9
10url='https://www.curseforge.com/minecraft/mc-mods/patchouli'
11arch=('any')
12license=('MIT')
13pkgdesc="Patchouli is a mod that aims to provide easy to implement, data-driven documentation for minecraft modders and modpack makers alike."
14
15source=(https://github.com/VazkiiMods/Patchouli/blob/$minver.x/LICENSE
16 https://mediafiles.forgecdn.net/files/3877/555/Patchouli-1.19-75.jar)
17depends=("forge-server=41.1.0"
18 "forge-server-hooks=1.0.0")
19noextract=(Patchouli-1.19-75.jar)
20sha256sums=('ae651cfe7715ce791261be76c1b7d1e502c40502b7e2b7658bdac2d64157236b'
21 'ce8dc7f0d2d2b4dca0071a7cb36a9c8ade355d81607ea653a00f42972a47e790')
22
23provides=(patchouli-forge)
24replaces=(patchouli-forge)
25conflicts=(patchouli-forge)
26
27package() {
28 install -Dm 2755 $srcdir/Patchouli-1.19-75.jar $pkgdir/srv/$srvname/mods/$modname.jar
29
30 install -Dm 644 $srcdir/LICENSE ${pkgdir}/usr/share/licenses/${pkgname}/LICENSE
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion