hercules
maintainer pilotmattk
· 3 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source URL is on a project-specific domain (hercules-390.eu) which is plausibly official for the project; the download is a standard source tarball, not a prebuilt binary, and the build process is transparent; the non-whitelisted host is not inherently risky given the context of a legitimate project-hosted source.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source URL is on a project-specific domain (hercules-390.eu) which is plausibly official for the project; the download is a standard source tarball, not a prebuilt binary, and the build process is transparent; the non-whitelisted host is not inherently risky given the context of a legitimate project-hosted source.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
source=("http://downloads.hercules-390.eu/$pkgname-${pkgver%.00}.tar.gz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer:
2
# Contributor: Alexander F Rødseth <xyproto@archlinux.org>
3
# Contributor: Kevin Piche <kevin@archlinux.org>
4
# Contributor: Jaroslav Lichtblau <svetlemodry@archlinux.org>
5
# Contributor: Tom Newsom <Jeepster@gmx.co.uk>
6
7
pkgname=hercules
8
pkgver=3.13.00
9
pkgrel=3
10
pkgdesc='Software implementation of System/370 and ESA/390'
11
arch=('x86_64')
12
url='http://www.hercules-390.eu/'
13
license=('custom')
14
depends=('bzip2' 'libnsl' 'zlib')
15
options=('!makeflags')
16
source=("http://downloads.hercules-390.eu/$pkgname-${pkgver%.00}.tar.gz")
17
sha512sums=('76f75ef3f1eb10c0fac0d6fa1ab9809b8d1dfe3deccbcd69366b05ee58f1ecb8ea0f387f7201ab4722b121478676f00e707ad27b6ecf1980fb09e900de63d718')
18
19
prepare() {
20
ln -sf "$pkgname-${pkgver%.00}" p
21
# Change module extension from .la to .so.
22
sed '/HDL_MODULE_SUFFIX/ s/\.la/.so/' -i p/hdl.h
23
}
24
25
build() {
26
cd p
27
./configure --prefix=/usr --enable-optimization=-O3
28
make
29
}
30
31
package() {
32
cd p
33
DESTDIR="$pkgdir" make install
34
install -Dm644 COPYRIGHT "$pkgdir/usr/share/licenses/hercules/qpl1"
35
}
36
37
# vim: ts=2 sw=2 et:
38
# getver: raw.githubusercontent.com/rbowler/spinhawk/master/makemsi/Hercules-W64.VER
39
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |