frhelper
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=("${pkgname}-${pkgver}.deb::https://static.frdic.com/pkg/${pkgname}.deb?v=${_date}")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from static.frdic.com, which is the official CDN/distribution host for the Eudic/FRHelper proprietary dictionary software (eudic.net). This is a vendor-controlled host, not a random personal or unofficial host. However, the source URL uses a query parameter (?v=date) rather than a versioned path, meaning the same URL could serve different content over time — the sha512sum provides integrity protection for the specific downloaded file, which mitigates substitution risk. The package installs a prebuilt proprietary binary (not compiled from source), which is inherently a supply-chain trust concern, but this is standard practice for proprietary software AUR packages. The DLAGENTS override with a custom User-Agent is unusual but explained in a comment (server returns 404 without it). Overall this is a legitimate proprietary software package from its official distribution host with a checksum, making it a borderline medium — the main concern is the prebuilt binary from a proprietary vendor CDN, which is the standard risk level for such packages in the AUR.
PKGBUILD
1 offending line(s) highlighted# Maintainer: sukanka <su975853527 at gmail dot com>
pkgname=frhelper
pkgver=13.5.2
_date=2024-08-25
_lang=fr
_flang=French
pkgrel=2
pkgdesc="Proprietary ${_flang} dictionary software for linux"
arch=('x86_64')
url="https://www.eudic.net/v4/${_lang}/app/${pkgname}"
license=('unknown')
depends=(
'hicolor-icon-theme'
)
provides=("eudic-${_lang}")
source=("${pkgname}-${pkgver}.deb::https://static.frdic.com/pkg/${pkgname}.deb?v=${_date}")
sha512sums=('cf62206e13afdbce2dd75e9b077ec6a73717138536ac25a64496ba74ba7fb79da3194534cf7e2fe8765f377552a529465f6c922199bf2766cda260346996028a')
# sometime use curl to download source deb, throws 404 not found.
# user other UA instead of origion one fixed it.
# https://wiki.archlinux.org/index.php/Nonfree_applications_package_guidelines#Custom_DLAGENTS
DLAGENTS=("https::/usr/bin/curl -A 'Mozilla' -fLC - --retry 3 --retry-delay 3 -o %o %u")
prepare() {
mkdir -p build
tar -xf data.tar.xz -C build
}
package() {
_dirname=eusoft-${pkgname}
install -dm755 ${pkgdir}/usr/share
cp -pvr build/usr/share/* ${pkgdir}/usr/share/
# link executable
install -dm755 ${pkgdir}/usr/bin/
ln -s /usr/share/${_dirname}/${pkgname} \
${pkgdir}/usr/bin/${pkgname}
# desktop entry
sed -i "s|/usr/share/${_dirname}/AppRun|${pkgname}|g" \
${pkgdir}/usr/share/applications/eusoft-${pkgname}.desktop
# remove unused files.
rm -rf ${pkgdir}/usr/share/${_dirname}/{gstreamer-1.0,libcrypto.so.1.0.0,libssl.so.1.0.0,AppRun,lib*.so*}
# keep qt lib and plugins
pushd ${pkgdir}/usr/share/${_dirname}/lib
find . -not -name 'libQt*' -not -name 'libicu*' -type f -delete
popd
}
# vim: ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |