intel-oneapi-basekit-2025
The source is a prebuilt installer from Intel's official download domain, which is a legitimate and expected source for this proprietary toolkit; the non-whitelisted host is part of Intel's registration center, not a third-party or swappable host, so the risk is low despite the static analyzer flag.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt installer from Intel's official download domain, which is a legitimate and expected source for this proprietary toolkit; the non-whitelisted host is part of Intel's registration center, not a third-party or swappable host, so the risk is low despite the static analyzer flag.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("${pkgname}-${pkgver}.sh::https://registrationcenter-download.intel.com/akdlm/IRC_NAS/${_urlmagic}/intel-oneapi-base-toolkit-${_pkgver}_offline.sh")
PKGBUILD
1 offending line(s) highlighted# Maintainer: lanxia <lanxia@gmail>
pkgname=intel-oneapi-basekit-2025
pkgver=2025.3.2
_pkgver=2025.3.2.21
_urlmagic=99f4837a-25b7-425d-a897-60af022676ea
pkgrel=1
pkgdesc="Intel oneAPI Base Toolkit for Linux"
arch=('x86_64')
url='https://software.intel.com/content/www/us/en/develop/tools/oneapi.html'
license=('LicenseRef-Intel-EULA-Developer-Tools AND LicenseRef-Intel-Simplified')
source=("${pkgname}-${pkgver}.sh::https://registrationcenter-download.intel.com/akdlm/IRC_NAS/${_urlmagic}/intel-oneapi-base-toolkit-${_pkgver}_offline.sh")
sha256sums=('fbca4d913f0afc73c8de1408a07e7d9cd12c68648c51c72802b709232f13f39c')
depends=(level-zero-loader)
options=(!strip staticlibs)
install="intel-oneapi-base-toolkit.install"
noextract=("${pkgname}-${pkgver}.sh")
optdepends=('libnotify: VTune GUI'
'glib2: VTune GUI'
'gtk3: VTune GUI'
'at-spi2-atk: VTune GUI'
'libdrm: VTune GUI'
'libxcb: VTune GUI'
'libxcrypt-compat: VTune GUI'
'xdg-utils: VTune GUI'
'nss: Advisor GUI')
conflicts=('intel-oneapi-base-toolkit' 'intel-oneapi-basekit')
provides=('intel-oneapi-base-toolkit' 'intel-oneapi-basekit'
'intel-oneapi-mkl' 'intel-oneapi-dnnl' 'intel-oneapi-tbb' 'intel-oneapi-dpl'
'intel-oneapi-ccl' 'intel-oneapi-dpcpp-cpp-compiler' 'intel-oneapi-dal' 'intel-oneapi-tcm'
'intel-oneapi-compiler-shared-runtime-libs' 'intel-oneapi-compiler-shared-opencl-cpu'
'intel-oneapi-compiler-shared-runtime' 'intel-oneapi-compiler-dpcpp-cpp-runtime-libs'
'intel-oneapi-compiler-dpcpp-cpp-runtime' 'intel-oneapi-compiler-shared' 'intel-oneapi-openmp'
'intel-oneapi-dpcpp-debugger' 'intel-oneapi-dev-utilities' 'intel-oneapi-dpcpp-cpp'
'intel-oneapi-vpl' 'intel-oneapi-ipp' 'intel-oneapi-ippcp' 'intel-oneapi-advisor'
'intel-oneapi-vtune' 'intel-oneapi-fpga-group' "intel-oneapi-basekit=${pkgver}")
build() {
sh "${pkgname}-${pkgver}.sh" \
--extract-folder "${srcdir}" --extract-only \
--remove-extracted-files no --log "${srcdir}"/extract.log
}
package() {
# we have to run as a user different from root
# otherwise the installer wants to write to /opt, /var
# which is not possible in fakeroot
LD_PRELOAD="" "intel-oneapi-base-toolkit-${_pkgver}_offline"/install.sh \
--silent --eula accept \
--components all \
--install-dir "${pkgdir}"/opt/intel/oneapi \
--log-dir "${srcdir}"/ --ignore-errors
# Remove install logs to make package reproducible.
rm -r "${pkgdir}/opt/intel/oneapi/logs"
# allow low level compiler libs to be found
local _lib_path='/opt/intel/oneapi/compiler'
local _ldso_conf="${pkgdir}"/etc/ld.so.conf.d
install -d "${_ldso_conf}"
echo "${_lib_path}/latest/lib" >> "${_ldso_conf}/${pkgname}.conf"
echo "${_lib_path}/latest/opt/compiler/lib" >> "${_ldso_conf}/${pkgname}.conf"
# Collection of licenses used in OneAPI with pointers for all toolkits
local majmin=$(echo "${pkgver}" | cut -d. -f1,2)
install -Dm644 "${pkgdir}/opt/intel/oneapi/licensing/latest/licensing/${majmin}/license.htm" \
"${pkgdir}/usr/share/licenses/${pkgname}/license.htm"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |