jflap
The package downloads a JAR file from a university-hosted subdomain, which is plausibly the project's official source; the JAR is installed as-is without obfuscation or remote code execution, and the rest of the package consists of local install scripts and assets, making the realistic worst-case a compromised JAR from the project itself, not a supply-chain attack via a third-party host.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a JAR file from a university-hosted subdomain, which is plausibly the project's official source; the JAR is installed as-is without obfuscation or remote code execution, and the rest of the package consists of local install scripts and assets, making the realistic worst-case a compromised JAR from the project itself, not a supply-chain attack via a third-party host.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
"http://www2.cs.duke.edu/csed/jflap/jflaptmp/july27-18/JFLAP${pkgver}.jar"
PKGBUILD
1 offending line(s) highlighted# Maintainer: robertfoster
pkgname=jflap
pkgver=7.1
pkgrel=3
pkgdesc="Software to learning the basic concepts of Formal Languages and Automata Theory"
arch=('any')
url="http://www.jflap.org/"
license=('CCPL')
noextract=("JFLAP${pkgver}.jar")
depends=('java-runtime')
source=(
"http://www2.cs.duke.edu/csed/jflap/jflaptmp/july27-18/JFLAP${pkgver}.jar"
"${pkgname}.sh"
"${pkgname}.desktop"
"${pkgname}.png"
)
package() {
cd ${srcdir}
install -Dm644 "JFLAP${pkgver}.jar" \
"${pkgdir}/opt/jflap/JFLAP.jar"
install -Dm755 "${pkgname}.sh" \
"${pkgdir}/usr/bin/jflap"
install -Dm644 "${srcdir}/${pkgname}.desktop" \
"${pkgdir}/usr/share/applications/${pkgname}.desktop"
install -Dm644 "${srcdir}/${pkgname}.png" \
"${pkgdir}/usr/share/pixmaps/${pkgname}.png"
}
sha256sums=('a22c095ddc56b18163e8ebeeef165b3a04cb570f35eb46b96105166e06c99406'
'b307592bda3aeb08ec3c07f33d89884e37da59daa0d81a9756b47f2e2a15e43c'
'2fec4a0d6b3b99216c28c404f38cb1ec06198eb7c610f7a814902b6fff302a77'
'67b7714c0b93b614a9821f2f1bb383f72ca364d28a33b0f3a34072d8f8d6dbcc')
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |