intel-oneapi-basekit-2025

maintainer lanxia · 2 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a prebuilt installer from Intel's official download domain, which is a legitimate and expected source for this proprietary toolkit; the non-whitelisted host is part of Intel's registration center, not a third-party or swappable host, so the risk is low despite the static analyzer flag.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt installer from Intel's official download domain, which is a legitimate and expected source for this proprietary toolkit; the non-whitelisted host is part of Intel's registration center, not a third-party or swappable host, so the risk is low despite the static analyzer flag.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("${pkgname}-${pkgver}.sh::https://registrationcenter-download.intel.com/akdlm/IRC_NAS/${_urlmagic}/intel-oneapi-base-toolkit-${_pkgver}_offline.sh")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: lanxia <lanxia@gmail>
2
3pkgname=intel-oneapi-basekit-2025
4pkgver=2025.3.2
5_pkgver=2025.3.2.21
6_urlmagic=99f4837a-25b7-425d-a897-60af022676ea
7pkgrel=1
8pkgdesc="Intel oneAPI Base Toolkit for Linux"
9arch=('x86_64')
10url='https://software.intel.com/content/www/us/en/develop/tools/oneapi.html'
11license=('LicenseRef-Intel-EULA-Developer-Tools AND LicenseRef-Intel-Simplified')
12source=("${pkgname}-${pkgver}.sh::https://registrationcenter-download.intel.com/akdlm/IRC_NAS/${_urlmagic}/intel-oneapi-base-toolkit-${_pkgver}_offline.sh")
13sha256sums=('fbca4d913f0afc73c8de1408a07e7d9cd12c68648c51c72802b709232f13f39c')
14depends=(level-zero-loader)
15options=(!strip staticlibs)
16install="intel-oneapi-base-toolkit.install"
17noextract=("${pkgname}-${pkgver}.sh")
18optdepends=('libnotify: VTune GUI'
19 'glib2: VTune GUI'
20 'gtk3: VTune GUI'
21 'at-spi2-atk: VTune GUI'
22 'libdrm: VTune GUI'
23 'libxcb: VTune GUI'
24 'libxcrypt-compat: VTune GUI'
25 'xdg-utils: VTune GUI'
26 'nss: Advisor GUI')
27conflicts=('intel-oneapi-base-toolkit' 'intel-oneapi-basekit')
28provides=('intel-oneapi-base-toolkit' 'intel-oneapi-basekit'
29 'intel-oneapi-mkl' 'intel-oneapi-dnnl' 'intel-oneapi-tbb' 'intel-oneapi-dpl'
30 'intel-oneapi-ccl' 'intel-oneapi-dpcpp-cpp-compiler' 'intel-oneapi-dal' 'intel-oneapi-tcm'
31 'intel-oneapi-compiler-shared-runtime-libs' 'intel-oneapi-compiler-shared-opencl-cpu'
32 'intel-oneapi-compiler-shared-runtime' 'intel-oneapi-compiler-dpcpp-cpp-runtime-libs'
33 'intel-oneapi-compiler-dpcpp-cpp-runtime' 'intel-oneapi-compiler-shared' 'intel-oneapi-openmp'
34 'intel-oneapi-dpcpp-debugger' 'intel-oneapi-dev-utilities' 'intel-oneapi-dpcpp-cpp'
35 'intel-oneapi-vpl' 'intel-oneapi-ipp' 'intel-oneapi-ippcp' 'intel-oneapi-advisor'
36 'intel-oneapi-vtune' 'intel-oneapi-fpga-group' "intel-oneapi-basekit=${pkgver}")
37
38build() {
39 sh "${pkgname}-${pkgver}.sh" \
40 --extract-folder "${srcdir}" --extract-only \
41 --remove-extracted-files no --log "${srcdir}"/extract.log
42}
43
44package() {
45 # we have to run as a user different from root
46 # otherwise the installer wants to write to /opt, /var
47 # which is not possible in fakeroot
48 LD_PRELOAD="" "intel-oneapi-base-toolkit-${_pkgver}_offline"/install.sh \
49 --silent --eula accept \
50 --components all \
51 --install-dir "${pkgdir}"/opt/intel/oneapi \
52 --log-dir "${srcdir}"/ --ignore-errors
53
54 # Remove install logs to make package reproducible.
55 rm -r "${pkgdir}/opt/intel/oneapi/logs"
56
57 # allow low level compiler libs to be found
58 local _lib_path='/opt/intel/oneapi/compiler'
59 local _ldso_conf="${pkgdir}"/etc/ld.so.conf.d
60 install -d "${_ldso_conf}"
61 echo "${_lib_path}/latest/lib" >> "${_ldso_conf}/${pkgname}.conf"
62 echo "${_lib_path}/latest/opt/compiler/lib" >> "${_ldso_conf}/${pkgname}.conf"
63
64 # Collection of licenses used in OneAPI with pointers for all toolkits
65 local majmin=$(echo "${pkgver}" | cut -d. -f1,2)
66 install -Dm644 "${pkgdir}/opt/intel/oneapi/licensing/latest/licensing/${majmin}/license.htm" \
67 "${pkgdir}/usr/share/licenses/${pkgname}/license.htm"
68}
69

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion