icc-hp-x520
maintainer dreieck
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads color profile data files (ICM/ICC) from a non-whitelisted but plausible project-related host; these are non-executable data files used for color calibration, posing minimal risk even if the source were swapped.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads color profile data files (ICM/ICC) from a non-whitelisted but plausible project-related host; these are non-executable data files used for color calibration, posing minimal risk even if the source were swapped.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
"https://www.redrivercatalog.com/profiles/hp-x520/rr-all-hp-x520-series.zip"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: dreieck
2
3
_pkgname="icc-hp-x520"
4
pkgname="${_pkgname}"
5
pkgver=2023_07
6
pkgrel=1
7
pkgdesc="ICM profiles for HP PhotoSmart 5520, 6520 and 7520 printers"
8
arch=('any')
9
url="https://www.redrivercatalog.com/profiles/hp-photosmart-6520-7520-icc-color-printer-profiles.html"
10
license=('Custom')
11
source=(
12
"https://www.redrivercatalog.com/profiles/hp-x520/rr-all-hp-x520-series.zip"
13
"copyright.txt"
14
)
15
sha256sums=(
16
'2bf98b53f75f685286228afe19a9e1146ab41bf611c0b44e0f4bebd6b31ee6bc'
17
'e4019ad406f496e4c25d74781d5c8f723a8047704c4da3bb15f9c27428fea2ae'
18
)
19
20
package() {
21
if stat --printf='' "${srcdir}"/*.icm 2>/dev/null; then
22
for _profile in "${srcdir}"/*.icm; do
23
install -D -v -m644 "${_profile}" "${pkgdir}/usr/share/color/icc/hp-x520/$(basename "${_profile}" .icm).icc"
24
done
25
fi
26
if stat --printf='' "${srcdir}"/*.icc 2>/dev/null; then
27
for _profile in "${srcdir}"/*.icc; do
28
install -D -v -m644 "${_profile}" "${pkgdir}/usr/share/color/icc/hp-x520/$(basename "${_profile}")"
29
done
30
fi
31
install -D -v -m644 "${srcdir}/profile-instructions-all.pdf" "${pkgdir}/usr/share/doc/${_pkgname}/profile-instructions-all.pdf"
32
install -D -v -m644 "${srcdir}/copyright.txt" "${pkgdir}/usr/share/licenses/${pkgname}/copyright.txt"
33
}
34
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |