gdb-static-bin

LOW
maintainer roddyrap 1 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package installs precompiled static binaries from a GitHub release, which is a supply-chain risk if the source is compromised, but the binaries are from a plausible project owner's repository and checksums are provided, limiting the risk to low.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs precompiled static binaries from a GitHub release, which is a supply-chain risk if the source is compromised, but the binaries are from a plausible project owner's repository and checksums are provided, limiting the risk to low.

PKGBUILD

1# Maintainer: Roddy Rappaport <roddy.rappaport@gmail.com>
2
3pkgname=gdb-static-bin
4pkgver=18.1
5pkgrel=1
6
7provides=("gdb-static")
8
9pkgdesc="Precompiled binaries of a statically linked versions of GDB with python. From the source repository's releases tab."
10arch=('x86_64' 'aarch64' 'armv7h')
11url='https://github.com/guyush1/gdb-static'
12license=('GPL-3.0-or-later')
13
14options=(!debug !strip)
15
16source_x86_64=("https://github.com/guyush1/gdb-static/releases/download/v${pkgver}-static/gdb-static-full-x86_64.tar.gz")
17sha256sums_x86_64=("6691734087a7523c2706ddf4026ea0ce565fc519a9306d2e4e5642a22705a188")
18
19source_aarch64=("https://github.com/guyush1/gdb-static/releases/download/v${pkgver}-static/gdb-static-full-aarch64.tar.gz")
20sha256sums_aarch64=("58b4f94c16e3d51d595ae497fbdb1b8bd43083487da9a2121313beae4fe22045")
21
22source_armv7h=("https://github.com/guyush1/gdb-static/releases/download/v${pkgver}-static/gdb-static-full-arm.tar.gz")
23sha256sums_armv7h=("f85bb9496279dfce5ff36c246340dba074b4e9cc00ecf1b3092aef0252b38713")
24
25package() {
26 local out_bin_dir="${pkgdir}/usr/bin/"
27 mkdir -p "${out_bin_dir}"
28
29 local out_licenses_dir="${pkgdir}/usr/share/licenses/${pkgname}"
30 mkdir -p "${out_licenses_dir}"
31
32 cp "${srcdir}/NOTICES" "${out_licenses_dir}/"
33
34 # Manually add a custom "-static" suffix so the binaries won't conflice with gdb. Additionally
35 # only take gdb and gdb-server (There are some binaries that aren't really related to gdb, so
36 # taking all of them seems wasteful. If anybody want them they can be added later).
37 for filename in "gdb" "gdbserver"; do
38 cp "${srcdir}/${filename}" "${out_bin_dir}/${filename}-static"
39 done
40}
41
42

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion