intel-oneapi-basekit-2025

LOW
maintainer lanxia 2 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a prebuilt installer from Intel's official download domain, which is a legitimate and expected source for this proprietary toolkit; the non-whitelisted host is part of Intel's registration center, not a third-party or swappable host, so the risk is low despite the static analyzer flag.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt installer from Intel's official download domain, which is a legitimate and expected source for this proprietary toolkit; the non-whitelisted host is part of Intel's registration center, not a third-party or swappable host, so the risk is low despite the static analyzer flag.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("${pkgname}-${pkgver}.sh::https://registrationcenter-download.intel.com/akdlm/IRC_NAS/${_urlmagic}/intel-oneapi-base-toolkit-${_pkgver}_offline.sh")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: lanxia <lanxia@gmail>
2
3pkgname=intel-oneapi-basekit-2025
4pkgver=2025.3.2
5_pkgver=2025.3.2.21
6_urlmagic=99f4837a-25b7-425d-a897-60af022676ea
7pkgrel=1
8pkgdesc="Intel oneAPI Base Toolkit for Linux"
9arch=('x86_64')
10url='https://software.intel.com/content/www/us/en/develop/tools/oneapi.html'
11license=('LicenseRef-Intel-EULA-Developer-Tools AND LicenseRef-Intel-Simplified')
12source=("${pkgname}-${pkgver}.sh::https://registrationcenter-download.intel.com/akdlm/IRC_NAS/${_urlmagic}/intel-oneapi-base-toolkit-${_pkgver}_offline.sh")
13sha256sums=('fbca4d913f0afc73c8de1408a07e7d9cd12c68648c51c72802b709232f13f39c')
14depends=(level-zero-loader)
15options=(!strip staticlibs)
16install="intel-oneapi-base-toolkit.install"
17noextract=("${pkgname}-${pkgver}.sh")
18optdepends=('libnotify: VTune GUI'
19 'glib2: VTune GUI'
20 'gtk3: VTune GUI'
21 'at-spi2-atk: VTune GUI'
22 'libdrm: VTune GUI'
23 'libxcb: VTune GUI'
24 'libxcrypt-compat: VTune GUI'
25 'xdg-utils: VTune GUI'
26 'nss: Advisor GUI')
27conflicts=('intel-oneapi-base-toolkit' 'intel-oneapi-basekit')
28provides=('intel-oneapi-base-toolkit' 'intel-oneapi-basekit'
29 'intel-oneapi-mkl' 'intel-oneapi-dnnl' 'intel-oneapi-tbb' 'intel-oneapi-dpl'
30 'intel-oneapi-ccl' 'intel-oneapi-dpcpp-cpp-compiler' 'intel-oneapi-dal' 'intel-oneapi-tcm'
31 'intel-oneapi-compiler-shared-runtime-libs' 'intel-oneapi-compiler-shared-opencl-cpu'
32 'intel-oneapi-compiler-shared-runtime' 'intel-oneapi-compiler-dpcpp-cpp-runtime-libs'
33 'intel-oneapi-compiler-dpcpp-cpp-runtime' 'intel-oneapi-compiler-shared' 'intel-oneapi-openmp'
34 'intel-oneapi-dpcpp-debugger' 'intel-oneapi-dev-utilities' 'intel-oneapi-dpcpp-cpp'
35 'intel-oneapi-vpl' 'intel-oneapi-ipp' 'intel-oneapi-ippcp' 'intel-oneapi-advisor'
36 'intel-oneapi-vtune' 'intel-oneapi-fpga-group' "intel-oneapi-basekit=${pkgver}")
37
38build() {
39 sh "${pkgname}-${pkgver}.sh" \
40 --extract-folder "${srcdir}" --extract-only \
41 --remove-extracted-files no --log "${srcdir}"/extract.log
42}
43
44package() {
45 # we have to run as a user different from root
46 # otherwise the installer wants to write to /opt, /var
47 # which is not possible in fakeroot
48 LD_PRELOAD="" "intel-oneapi-base-toolkit-${_pkgver}_offline"/install.sh \
49 --silent --eula accept \
50 --components all \
51 --install-dir "${pkgdir}"/opt/intel/oneapi \
52 --log-dir "${srcdir}"/ --ignore-errors
53
54 # Remove install logs to make package reproducible.
55 rm -r "${pkgdir}/opt/intel/oneapi/logs"
56
57 # allow low level compiler libs to be found
58 local _lib_path='/opt/intel/oneapi/compiler'
59 local _ldso_conf="${pkgdir}"/etc/ld.so.conf.d
60 install -d "${_ldso_conf}"
61 echo "${_lib_path}/latest/lib" >> "${_ldso_conf}/${pkgname}.conf"
62 echo "${_lib_path}/latest/opt/compiler/lib" >> "${_ldso_conf}/${pkgname}.conf"
63
64 # Collection of licenses used in OneAPI with pointers for all toolkits
65 local majmin=$(echo "${pkgver}" | cut -d. -f1,2)
66 install -Dm644 "${pkgdir}/opt/intel/oneapi/licensing/latest/licensing/${majmin}/license.htm" \
67 "${pkgdir}/usr/share/licenses/${pkgname}/license.htm"
68}
69

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion