idos-timetable-data-chaps-trains-cz-2026-latest
The package downloads timetable data and a license file from the official project host chaps.cz and its subdomain ttask.chaps.cz; despite the non-whitelisted host, this is the project's legitimate source, the data is non-executable, and the package otherwise follows standard AUR practices without signs of malicious behavior.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads timetable data and a license file from the official project host chaps.cz and its subdomain ttask.chaps.cz; despite the non-whitelisted host, this is the project's legitimate source, the data is non-executable, and the package otherwise follows standard AUR practices without signs of malicious behavior.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:66
"${_target}::https://ttakt.chaps.cz/TTAktual/Win/Zip/${_zipfile}" -
PKGBUILD:67
"IDOS-Licence.pdf::https://chaps.cz/files/idos/IDOS-Licence.pdf"
PKGBUILD
2 offending line(s) highlighted# Maintainer: dreieck
# PKGBUILD last time manually edited: At least on 2025-12-10.
_year='26'
_prevyear="$(( ${_year} - 1 ))"
_zipfile="VLAK${_year}C.ZIP"
url="https://chaps.cz/eng/download/idos/zip#kotvatt"
#url="http://chaps.cz/eng/download/idos-new/zip#kotvatt" # URL valid for the time when the timetable is still in the future.
_pkgver() {
# Reason for a _pkgver(): Have something to run before source download so that we can have version aware source downloads.
# Do not use metadata of the source file, but do website parsing: So we do not need to download the file to (AUR-)update the package version with our own crude hacked script 'idos-aur-update-versions.sh'.
#date -r "${srcdir}/${_target}" +"%Y_%m_%d"
wget -nv -O- "${url}" | tr -d '\a' | tr '\n' '\a' | sed 's|^.*File '"${_zipfile}"'\(.*\)Zip/'"${_zipfile}"'.*$|\1\n|g' | tr '\a' '\n' | grep 'Update date:' | cut -d, -f1 | sed -r 's|([0-9]+)\.([0-9]+)\.([0-9]+).|\n\3_\2_\1\n|g' | grep -E '^[0-9]+_[0-9]+_[0-9]+' | sed -E -e 's|_([0-9])_|_0\1_|g' -e 's|_([0-9])$|_0\1|g'
}
_pkgname="idos-timetable-data-chaps-trains-cz-20${_year}"
pkgname="${_pkgname}-latest"
epoch=0
_pkgver="$(_pkgver)" # This should be set _before_ sources get downloaded.
pkgver="${_pkgver}"
pkgrel=1
pkgdesc="20${_prevyear}/20${_year} Timetable data for the timetable search engines by CHAPS: Czech trains."
arch=(any)
license=('custom')
groups=(
"idos-timetable"
)
depends=(
"idos-timetable-data-trains-common"
)
makedepends=(
"wget"
)
optdepends=(
"idos-timetable-tariff-trains-cz: For showing prices."
"idos-timetable-maps-trains-cz: For displaying routes on maps."
"idos-timetable-additionalinfo-trains-cz: For (links to) additional information about train composition and stations."
)
provides=(
"${_pkgname}=${pkgver}"
"idos-timetable-data=${pkgver}"
"idos-timetable-data-trains=${pkgver}"
"idos-timetable-data-trains-cz=${pkgver}"
"idos-timetable-data-trains-cz-20${_year}=${pkgver}"
)
replaces=(
'idos-timetable-data-chaps-trains-cz-latest'
)
conflicts=(
"${_pkgname}"
### The conflict will be handled by idos-timetable-data-chaps-all, if needed. Sometimes idos-timetable-data-chaps-all does not provide the train data, and then idos-timetable-data-chaps-all will depend on this package, thus this package should not have idos-timetable-data-chaps-all as conflict.
# "idos-timetable-data-chaps-all"
)
_target="vlak${_year}c-${_pkgver}.zip"
source=(
"${_target}::https://ttakt.chaps.cz/TTAktual/Win/Zip/${_zipfile}"
"IDOS-Licence.pdf::https://chaps.cz/files/idos/IDOS-Licence.pdf"
"license-dummy.txt"
)
sha256sums=(
'SKIP'
"SKIP"
"c6bb216055d3670d3100b7a74e04ce0644030f365f4349a09e630ef60fbcb9a4"
)
pkgver() {
printf '%s' "${_pkgver}"
}
package() {
_instdirbase='/opt/idos-timetable'
_instdir="${pkgdir}/${_instdirbase}"
install -d -m755 "${_instdir}"
cp -r "${srcdir}"/Data* "${_instdir}/"
chmod 755 "${_instdir}"/Data*
chmod 644 "${_instdir}"/Data*/*
rm -f "${_instdir}/Data1"/[vV][lL][aA][kK].[tT][tT][rR] # This one is provided by idos-timetable-data-trains-common.
install -d -m755 "${pkgdir}/usr/share/doc/${_pkgname}"
echo "${url}" > "${pkgdir}/usr/share/doc/${_pkgname}/info.url"
chmod 644 "${pkgdir}/usr/share/doc/${_pkgname}/info.url"
install -D -m644 "${srcdir}/license-dummy.txt" "${pkgdir}/usr/share/licenses/${pkgname}/copying.txt"
install -D -m644 "${srcdir}/IDOS-Licence.pdf" "${pkgdir}/usr/share/licenses/${pkgname}/IDOS-Licence.pdf"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 18:00:42 | Medium | 1 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |