ixxat-socketcan-dkms

maintainer phippu · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a driver tarball from a plausible official vendor domain (HMS Networks) used to build a DKMS module;虽 hosted on Azure Blob Storage, it is part of the vendor's documented download infrastructure, and the checksum is verified, making it a legitimate build artifact rather than an untrusted executable.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a driver tarball from a plausible official vendor domain (HMS Networks) used to build a DKMS module;虽 hosted on Azure Blob Storage, it is part of the vendor's documented download infrastructure, and the checksum is verified, making it a legitimate build artifact rather than an untrusted executable.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("https://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/ixxat/monitored/pc-interface-cards/socketcan-linux.gz?sfvrsn=3eb48d7_89&download=true"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Philippe Schenker <dev@pschenker.ch>
2
3name=ixxat-socketcan
4pkgname="${name}-dkms"
5pkgver=2.0.520
6pkgrel=5
7pkgdesc="DKMS SocketCAN driver for IXXAT USB-to-CAN v2"
8arch=("i686" "x86_64")
9url="https://www.hms-networks.com/support/general-downloads"
10license=("GPL2")
11optdepends=("can-utils: Linux-CAN / SocketCAN user space applications")
12depends=("dkms")
13source=("https://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/ixxat/monitored/pc-interface-cards/socketcan-linux.gz?sfvrsn=3eb48d7_89&download=true"
14 "makefile_use_kernelrelease_variable_insead_of_uname_r.patch"
15 "dkms.conf"
16 "0001-ixxat_usb-Fix-for-new-can_priv-naming.patch")
17sha256sums=("dd34dfb4e1c988693c2b6799c467ba7689758c9757fa8e8e4890fa7715b818b6"
18 "ddc8a7d67e9c1490d9dc4c1f434b8832969d84ff6ea796e5b3a2ad196e3cf80d"
19 "1a7f4502869171cc1dc617e670f018309af1a7bd0a352108002c75a55bb3016c"
20 "526358675a7edad14f84ef0a78c29cf3628e2831a975fd3f709ad0107f2be518")
21
22prepare() {
23 local kernel_ver=$(pacman -Q linux | awk '{print $2}' | cut -d- -f1)
24
25 mkdir -p "${srcdir}/${name}-${pkgver}"
26 cd "${srcdir}/${name}-${pkgver}"
27 tar xzfv "../ix_usb_can_2.0.520-REL.tgz"
28 cp ../dkms.conf .
29 sed "s/@PKGVER@/${pkgver}/" -i dkms.conf
30 sed "s/@PKGNAME@/${name}/" -i dkms.conf
31 patch -p 1 -i ../makefile_use_kernelrelease_variable_insead_of_uname_r.patch
32
33 if [[ $(vercmp "$kernel_ver" "6.17") -ge 0 ]]; then
34 patch -p 1 -i ../0001-ixxat_usb-Fix-for-new-can_priv-naming.patch
35 fi
36}
37
38package() {
39 dkmsdir="${pkgdir}/usr/src/${name}-${pkgver}/"
40 install -d "${dkmsdir}"
41 cp -a "${srcdir}/${name}-${pkgver}/." "${dkmsdir}"
42}
43

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion