idos-timetable-maps-chaps-all-latest
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The package downloads map data (a ZIP of timetable/map files) from ttakt.chaps.cz, which is the official CHAPS (Czech timetable software vendor) update server — the same company whose main site (chaps.cz) is referenced throughout the PKGBUILD. The content installed is pure data files (Data* directories with 644 permissions), not executed binaries or libraries. The SKIP checksums are a legitimate concern for integrity but are used here because the file is a rolling/latest release whose hash changes with each update — a common pattern for 'latest' AUR packages. The version is scraped from the vendor's own download page. There is no code execution of downloaded content, no obfuscation, and no unofficial/personal host involved. The risk is low (no checksum verification), not medium (no executed foreign code).
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:83
"${_target}::https://ttakt.chaps.cz/TTAktual/Win/Zip/${_zipfile}" -
PKGBUILD:84
"IDOS-Licence.pdf::https://chaps.cz/files/idos/IDOS-Licence.pdf"
PKGBUILD
2 offending line(s) highlighted# Maintainer: dreieck
# PKGBUILD last time manually edited: At least on 2024-12-17.
url="https://chaps.cz/eng/download/idos/zip#kotvamap"
_zipfile="KOMPLET_M.ZIP"
_pkgver() {
# Reason for a _pkgver(): Have something to run before source download so that we can have version aware source downloads.
wget -nv -O- "${url}" | tr -d '\a' | tr '\n' '\a' | sed 's|^.*File '"${_zipfile}"'\(.*\)Zip/'"${_zipfile}"'.*$|\1\n|g' | tr '\a' '\n' | grep 'Update date:' | cut -d, -f1 | sed -r 's|([0-9]+)\.([0-9]+)\.([0-9]+).|\n\3_\2_\1\n|g' | grep -E '^[0-9]+_[0-9]+_[0-9]+' | sed -E -e 's|_([0-9])_|_0\1_|g' -e 's|_([0-9])$|_0\1|g'
}
_pkgname=idos-timetable-maps-chaps-all
pkgname="${_pkgname}-latest"
epoch=0
_pkgver="$(_pkgver)" # This should be set _before_ sources get downloaded.
pkgver="${_pkgver}"
pkgrel=1
pkgdesc="Map data for the timetable search engines by CHAPS: European railway, Czech/Slovak trains + bus, Czech public transport. Note that some timetables need the purchased version of IDOS to run."
arch=(any)
license=('custom')
groups=(
"idos-timetable"
)
depends=("idos-timetable-data")
makedepends=(
"wget"
)
optdepends=()
provides=(
"${_pkgname}=${pkgver}"
"idos-timetable-maps=${pkgver}"
"idos-timetable-maps-trains=${pkgver}"
"idos-timetable-maps-bus=${pkgver}"
"idos-timetable-maps-mhd=${pkgver}"
"idos-timetable-maps-mhd-cz=${pkgver}"
"idos-timetable-maps-trains-cz=${pkgver}"
"idos-timetable-maps-trains-sk=${pkgver}"
"idos-timetable-maps-trains-europe=${pkgver}"
"idos-timetable-maps-bus-cz=${pkgver}"
"idos-timetable-maps-bus-sk=${pkgver}"
"idos-timetable-maps-mhd-idsjmk=${pkgver}"
"idos-timetable-maps-mhd-ceskebudejovice=${pkgver}"
"idos-timetable-maps-mhd-jihlava=${pkgver}"
"idos-timetable-maps-mhd-olomouc=${pkgver}"
"idos-timetable-maps-mhd-odis=${pkgver}"
"idos-timetable-maps-mhd-pid=${pkgver}"
"idos-timetable-maps-mhd-trebic=${pkgver}"
"idos-timetable-maps-mhd-ustinl=${pkgver}"
"idos-timetable-maps-mhd-zlin=${pkgver}"
)
conflicts=(
"${_pkgname}"
"idos-timetable-maps-chaps-trains-europe"
"idos-timetable-maps-chaps-trains-cz"
"idos-timetable-maps-chaps-trains-sk"
"idos-timetable-maps-bus-cz"
"idos-timetable-maps-bus-sk"
"idos-timetable-maps-mhd-idsjmk"
"idos-timetable-maps-mhd-ceskebudejovice"
"idos-timetable-maps-mhd-jihlava"
"idos-timetable-maps-mhd-olomouc"
"idos-timetable-maps-mhd-odis"
"idos-timetable-maps-mhd-pid"
"idos-timetable-maps-mhd-trebic"
"idos-timetable-maps-mhd-ustinl"
"idos-timetable-maps-mhd-zlin"
)
_target="komplet_m-${_pkgver}.zip"
source=(
"${_target}::https://ttakt.chaps.cz/TTAktual/Win/Zip/${_zipfile}"
"IDOS-Licence.pdf::https://chaps.cz/files/idos/IDOS-Licence.pdf"
"license-dummy.txt"
)
sha256sums=(
'SKIP'
"SKIP"
"c6bb216055d3670d3100b7a74e04ce0644030f365f4349a09e630ef60fbcb9a4"
)
pkgver() {
printf '%s' "${_pkgver}"
}
package() {
_instdirbase='/opt/idos-timetable'
_instdir="${pkgdir}/${_instdirbase}"
install -d -m755 "${_instdir}"
cp -r "${srcdir}"/Data* "${_instdir}/"
chmod 755 "${_instdir}"/Data*
chmod 644 "${_instdir}"/Data*/*
install -d -m755 "${pkgdir}/usr/share/doc/${_pkgname}"
echo "${url}" > "${pkgdir}/usr/share/doc/${_pkgname}/info.url"
chmod 644 "${pkgdir}/usr/share/doc/${_pkgname}/info.url"
install -D -m644 "${srcdir}/license-dummy.txt" "${pkgdir}/usr/share/licenses/${pkgname}/copying.txt"
install -D -m644 "${srcdir}/IDOS-Licence.pdf" "${pkgdir}/usr/share/licenses/${pkgname}/IDOS-Licence.pdf"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |