idos-timetable-data-chaps-trains-europe-2026-latest

LOW
maintainer dreieck 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads timetable data and a license PDF from the official project host chaps.cz and its subdomain ttakt.chaps.cz; these are non-executable data files, so even though the host is not whitelisted and checksums are skipped, the risk is low as they cannot execute code.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads timetable data and a license PDF from the official project host chaps.cz and its subdomain ttakt.chaps.cz; these are non-executable data files, so even though the host is not whitelisted and checksums are skipped, the risk is low as they cannot execute code.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:77 "${_target}::https://ttakt.chaps.cz/TTAktual/Win/Zip/${_zipfile}"
  • PKGBUILD:78 "IDOS-Licence.pdf::https://chaps.cz/files/idos/IDOS-Licence.pdf"

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: dreieck
2
3# PKGBUILD last time manually edited: At least on 2025-12-10.
4
5_year='26'
6_prevyear="$(( ${_year} - 1 ))"
7url="https://chaps.cz/eng/download/idos/zip#kotvatt"
8#url="http://chaps.cz/eng/download/idos-new/zip#kotvatt" # URL valid for the time when the timetable is still in the future.
9_zipfile="VLAK${_year}E.ZIP"
10_pkgver() {
11 # Reason for a _pkgver(): Have something to run before source download so that we can have version aware source downloads.
12 # Do not use metadata of the source file, but do website parsing: So we do not need to download the file to (AUR-)update the package version with our own crude hacked script 'idos-aur-update-versions.sh'.
13 #date -r "${srcdir}/${_target}" +"%Y_%m_%d"
14
15 wget --user-agent='' --dns-timeout=30 --connect-timeout=30 --read-timeout=30 -q -O- "${url}" | tr -d '\a' | tr '\n' '\a' | sed 's|^.*File '"${_zipfile}"'\(.*\)Zip/'"${_zipfile}"'.*$|\1\n|g' | tr '\a' '\n' | grep 'Update date:' | cut -d, -f1 | sed -r 's|([0-9]+)\.([0-9]+)\.([0-9]+).|\n\3_\2_\1\n|g' | grep -E '^[0-9]+_[0-9]+_[0-9]+' | sed -E -e 's|_([0-9])_|_0\1_|g' -e 's|_([0-9])$|_0\1|g'
16 # wget --user-agent='' --dns-timeout=30 --connect-timeout=30 --read-timeout=30 --no-check-certificate -q -O- "${url}" | tr -d '\a' | tr '\n' '\a' | sed 's|^.*File '"${_zipfile}"'\(.*\)Zip/'"${_zipfile}"'.*$|\1\n|g' | tr '\a' '\n' | grep 'Update date:' | cut -d, -f1 | sed -r 's|([0-9]+)\.([0-9]+)\.([0-9]+).|\n\3_\2_\1\n|g' | grep -E '^[0-9]+_[0-9]+_[0-9]+' | sed -E -e 's|_([0-9])_|_0\1_|g' -e 's|_([0-9])$|_0\1|g'
17}
18
19_pkgname="idos-timetable-data-chaps-trains-europe-20${_year}"
20pkgname="${_pkgname}-latest"
21epoch=0
22_pkgver="$(_pkgver)" # This should be set _before_ sources get downloaded.
23pkgver="${_pkgver}"
24pkgrel=1
25pkgdesc="20${_prevyear}/20${_year} Timetable data for the timetable search engines by CHAPS: European trains."
26arch=(any)
27license=('custom')
28
29groups=(
30 "idos-timetable"
31 )
32
33depends=(
34 "idos-timetable-data-trains-common"
35 )
36
37makedepends=(
38 "wget"
39)
40
41optdepends=(
42 "idos-timetable-tariff-trains-europe: For showing prices."
43 "idos-timetable-tariff-trains-cz: For showing prices (for Czech Republic only)."
44 "idos-timetable-tariff-trains-sk: For showing prices (for Slovakia only)."
45 "idos-timetable-maps-trains-europe: For displaying routes on maps."
46 "idos-timetable-maps-trains-cz: For displaying routes on (for Czech Republic only)."
47 "idos-timetable-maps-trains-sk: For displaying routes on (for Slovakia only)."
48 "idos-timetable-additionalinfo-trains-europe: For (links to) additional information about train composition and stations."
49 "idos-timetable-additionalinfo-trains-cz: For (links to) additional information about train composition and stations (for Chech Republic only)"
50 "idos-timetable-additionalinfo-trains-sk: For (links to) additional information about train composition and stations (for Slovakia only)."
51 )
52
53provides=(
54 "${_pkgname}=${pkgver}"
55
56 "idos-timetable-data=${pkgver}"
57 "idos-timetable-data-trains=${pkgver}"
58
59 "idos-timetable-data-trains-europe=${pkgver}"
60 "idos-timetable-data-trains-europe-20${_year}=${pkgver}"
61)
62
63replaces=(
64 'idos-timetable-data-chaps-trains-europe-latest'
65)
66
67conflicts=(
68 "${_pkgname}"
69
70 ### The conflict will be handled by idos-timetable-data-chaps-all, if needed. Sometimes idos-timetable-data-chaps-all does not provide the train data, and then idos-timetable-data-chaps-all will depend on this package, thus this package should not have idos-timetable-data-chaps-all as conflict.
71 # "idos-timetable-data-chaps-all"
72)
73
74_target="vlak${_year}e-${_pkgver}.zip"
75
76source=(
77 "${_target}::https://ttakt.chaps.cz/TTAktual/Win/Zip/${_zipfile}"
78 "IDOS-Licence.pdf::https://chaps.cz/files/idos/IDOS-Licence.pdf"
79 "license-dummy.txt"
80)
81
82sha256sums=(
83 'SKIP'
84 "SKIP"
85 "c6bb216055d3670d3100b7a74e04ce0644030f365f4349a09e630ef60fbcb9a4"
86)
87
88pkgver() {
89 printf '%s' "${_pkgver}"
90}
91
92
93package() {
94 _instdirbase='/opt/idos-timetable'
95 _instdir="${pkgdir}/${_instdirbase}"
96 install -d -m755 "${_instdir}"
97
98 cp -r "${srcdir}"/Data* "${_instdir}/"
99 chmod 755 "${_instdir}"/Data*
100 chmod 644 "${_instdir}"/Data*/*
101 rm -f "${_instdir}/Data1"/[vV][lL][aA][kK].[tT][tT][rR] # This one is provided by idos-timetable-data-trains-common.
102
103 install -d -m755 "${pkgdir}/usr/share/doc/${_pkgname}"
104 echo "${url}" > "${pkgdir}/usr/share/doc/${_pkgname}/info.url"
105 chmod 644 "${pkgdir}/usr/share/doc/${_pkgname}/info.url"
106
107 install -D -m644 "${srcdir}/license-dummy.txt" "${pkgdir}/usr/share/licenses/${pkgname}/copying.txt"
108 install -D -m644 "${srcdir}/IDOS-Licence.pdf" "${pkgdir}/usr/share/licenses/${pkgname}/IDOS-Licence.pdf"
109}
110

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 18:00:42 Medium 1
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion