hashcash
maintainer azon
· 4 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is downloaded from the project's official website (hashcash.org), which is plausibly the project's own host, and the package builds from source without executing untrusted binaries or obfuscated code.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is downloaded from the project's official website (hashcash.org), which is plausibly the project's own host, and the package builds from source without executing untrusted binaries or obfuscated code.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=(http://www.hashcash.org/source/${pkgname}-${pkgver}.tgz)
PKGBUILD
1 offending line(s) highlighted
1
# $Id: PKGBUILD 266875 2017-11-15 14:29:11Z foutrelis $
2
# Maintainer: Sergej Pupykin <pupykin.s+arch@gmail.com>
3
# Maintainer: Charles Mauch <cmauch@gmail.com>
4
5
pkgname=hashcash
6
pkgver=1.22
7
pkgrel=5
8
pkgdesc="a denial-of-service counter measure tool for email/spam."
9
arch=('x86_64')
10
url="http://www.hashcash.org"
11
license=('GPL')
12
depends=( 'glibc' )
13
source=(http://www.hashcash.org/source/${pkgname}-${pkgver}.tgz)
14
md5sums=('31fae207061841dffc7b90ee18e3d0fa')
15
16
build() {
17
cd "$srcdir"/${pkgname}-${pkgver}
18
if [ "${CARCH}" = "x86_64" ]; then
19
make generic-openssl LIBCRYPTO=-lcrypto
20
else
21
make x86-openssl LIBCRYPTO=-lcrypto
22
fi
23
}
24
25
package() {
26
cd "$srcdir"/${pkgname}-${pkgver}
27
install -Dm755 hashcash "$pkgdir"/usr/bin/hashcash
28
install -Dm755 sha1 "$pkgdir"/usr/bin/sha1
29
install -Dm755 hashcash.1 "$pkgdir"/usr/share/man/man1/hashcash.1
30
}
31
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |