irpf2022

LOW
maintainer dbermond 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads a government-official IRPF program from a plausibly legitimate Brazilian tax authority host; the source is a prebuilt executable but from an official government domain, and the rest of the package consists of standard install steps for Java and desktop integration.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a government-official IRPF program from a plausibly legitimate Brazilian tax authority host; the source is a prebuilt executable but from an official government domain, and the rest of the package consists of standard install steps for Java and desktop integration.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:19 source=("https://downloadirpf.receita.fazenda.gov.br/irpf/${pkgver%%.*}/irpf/arquivos/IRPF${pkgver%%.*}-${pkgver#*.}.zip"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer : Daniel Bermond <dbermond@archlinux.org>
2
3pkgname=irpf2022
4pkgver=2022.2.3
5pkgrel=1
6pkgdesc='Brazilian physical person income tax (IRPF) program (2022 version)'
7arch=('any')
8url='https://www.gov.br/receitafederal/pt-br/centrais-de-conteudo/download/pgd/dirpf'
9license=('LicenseRef-Custom')
10depends=(
11 'hicolor-icon-theme'
12 'java-runtime=11'
13 'sh')
14optdepends=(
15 'cups: for print support'
16 'gvfs: for importing pre-filled data from a gov.br account')
17makedepends=(
18 'icoutils')
19source=("https://downloadirpf.receita.fazenda.gov.br/irpf/${pkgver%%.*}/irpf/arquivos/IRPF${pkgver%%.*}-${pkgver#*.}.zip"
20 'irpf.desktop'
21 'irpf.sh'
22 'LICENSE')
23sha256sums=('6a50be7833936ee843a88cdc5c0769031cbe2d35b37ae0b7b780b30db8683c79'
24 'da94b677c77a9637cda73811c133f9cb838a243916c497065fab5cd654c56edc'
25 '5b07c9124145ad8e2a8c436c759e17e8ab69304b6a5ddb5a0308b2382e4b4251'
26 'a406e102e2c10c202bd7a0ba775b004c0f04440544db73ce6923172a62aacd67')
27
28prepare() {
29 wrestool -x -t 14 -o "IRPF${pkgver%%.*}" "IRPF${pkgver%%.*}/IRPF${pkgver%%.*}.exe"
30 icotool -x -o "IRPF${pkgver%%.*}" "IRPF${pkgver%%.*}/IRPF${pkgver%%.*}.exe"_*_*_*.ico
31}
32
33package() {
34 install -D -m755 irpf.sh "${pkgdir}/usr/bin/${pkgname}"
35 install -D -m644 irpf.desktop "${pkgdir}/usr/share/applications/${pkgname}.desktop"
36 install -D -m644 LICENSE -t "${pkgdir}/usr/share/licenses/${pkgname}"
37 install -D -m644 "IRPF${pkgver%%.*}"/{{irpf,pgd-updater}.jar,IRPF2022.acb} -t "${pkgdir}/usr/share/java/${pkgname}"
38 install -D -m644 "IRPF${pkgver%%.*}/Leia-me.htm" -t "${pkgdir}/usr/share/doc/${pkgname}"
39 cp -dr --no-preserve='ownership' "IRPF${pkgver%%.*}/help" "${pkgdir}/usr/share/doc/${pkgname}"
40 cp -dr --no-preserve='ownership' "IRPF${pkgver%%.*}/"lib{,-modulos} "${pkgdir}/usr/share/java/${pkgname}"
41 ln -sr "${pkgdir}/usr/share/doc/${pkgname}/help" "${pkgdir}/usr/share/java/${pkgname}/help"
42
43 local _file
44 local _res
45 while read -r -d '' _file
46 do
47 _res="$(sed 's/\.png$//;s/^.*_//;s/x.*$//' <<< "$_file")"
48 install -D -m644 "$_file" "${pkgdir}/usr/share/icons/hicolor/${_res}x${_res}/apps/${pkgname}.png"
49 done < <(find "IRPF${pkgver%%.*}" -maxdepth 1 -type f -name "IRPF${pkgver%%.*}.exe"_*_*_*_*_*x*x*.png -print0)
50}
51

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion