jitsi-meet-nightly-bin
The package downloads official Jitsi Meet Web nightly .deb files from the project's own domain (download.jitsi.org), which is plausibly the project's official source; unpacks and installs static web assets (HTML, JS, config files) without executing remote code; the non-whitelisted host is the project's own release infrastructure, and the installed payload is non-executable frontend content.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads official Jitsi Meet Web nightly .deb files from the project's own domain (download.jitsi.org), which is plausibly the project's official source; unpacks and installs static web assets (HTML, JS, config files) without executing remote code; the non-whitelisted host is the project's own release infrastructure, and the installed payload is non-executable frontend content.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:25
"https://download.jitsi.org/unstable/jitsi-meet-web_${_version}-1_all.deb"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Celogeek <arch-aur-f5d67e@celogeek.com>
_basename=jitsi
_pkgname=meet
_version=1.0.9392
_pkgbase=${_basename}-${_pkgname}-nightly
_debname=${_basename}-${_pkgname}-web
pkgname=${_pkgbase}-bin
pkgver=${_version}
pkgrel=1
pkgdesc="Jitsi Meet Web nightly binary"
arch=('any')
url="https://jitsi.org/jitsi-meet/"
license=('Apache')
depends=()
optdepends=("nginx")
makedepends=('tar')
options=('!strip')
backup=(
"etc/webapps/${_pkgbase}/config.js"
"etc/webapps/${_pkgbase}/interface_config.js"
)
source=(
"https://download.jitsi.org/unstable/jitsi-meet-web_${_version}-1_all.deb"
"config_${_version}.deb::https://download.jitsi.org/unstable/jitsi-meet-web-config_${_version}-1_all.deb"
)
noextract=(
"config_${_version}.deb"
)
provides=(${_pkgbase})
conflicts=(${_pkgbase})
build() {
rm -rf ${_pkgbase}
mkdir ${_pkgbase}
tar xJf data.tar.xz -C ${_pkgbase}
ar p "config_${_version}.deb" data.tar.xz | tar xJC ${_pkgbase}
}
package() {
cd "$srcdir/${_pkgbase}"
DESTDIR="${pkgdir}/usr/share/webapps/${_pkgbase}"
CONFDIR="${pkgdir}/etc/webapps/${_pkgbase}"
DOCDIR="${pkgdir}/usr/share/doc/${_pkgbase}"
install -d "$DESTDIR"
install -d "$CONFDIR"
install -d "$DOCDIR"
cp -R usr/share/jitsi-meet/* "${DESTDIR}"
cp usr/share/jitsi-meet-web-config/config.js "${DESTDIR}"
cp -R usr/share/jitsi-meet-web-config/* "${DOCDIR}"
for i in interface_config.js config.js
do
install -Dm644 "$DESTDIR/${i}" "$CONFDIR/${i}"
ln -sf "/etc/webapps/${_pkgbase}/${i}" "$DESTDIR/${i}"
done
sed -i 's@/usr/share/jitsi-meet@/usr/share/webapps/'${_pkgbase}'@' "${pkgdir}/usr/share/doc/${_pkgbase}/"*
sed -i 's@/etc/jitsi/meet@/etc/webapps/'${_pkgbase}'@' "${pkgdir}/usr/share/doc/${_pkgbase}/"*
chown -R root:root "${pkgdir}"
}
sha256sums=('7db4b651ad3125fcc5c742cdf4f61e7323fd536714f5cba6fa9306561fa9a0b9'
'520a45c8db60a595e7f08e4d8f36afe567f8c7c93a6d606bd31e252ad1d08a8c')
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 13:40:34 | Medium | 1 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |