jitsi-meet-nightly-bin

LOW
maintainer celogeek 0 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads official Jitsi Meet Web nightly .deb files from the project's own domain (download.jitsi.org), which is plausibly the project's official source; unpacks and installs static web assets (HTML, JS, config files) without executing remote code; the non-whitelisted host is the project's own release infrastructure, and the installed payload is non-executable frontend content.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads official Jitsi Meet Web nightly .deb files from the project's own domain (download.jitsi.org), which is plausibly the project's official source; unpacks and installs static web assets (HTML, JS, config files) without executing remote code; the non-whitelisted host is the project's own release infrastructure, and the installed payload is non-executable frontend content.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:25 "https://download.jitsi.org/unstable/jitsi-meet-web_${_version}-1_all.deb"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Celogeek <arch-aur-f5d67e@celogeek.com>
2
3_basename=jitsi
4_pkgname=meet
5_version=1.0.9392
6
7_pkgbase=${_basename}-${_pkgname}-nightly
8_debname=${_basename}-${_pkgname}-web
9pkgname=${_pkgbase}-bin
10pkgver=${_version}
11pkgrel=1
12pkgdesc="Jitsi Meet Web nightly binary"
13arch=('any')
14url="https://jitsi.org/jitsi-meet/"
15license=('Apache')
16depends=()
17optdepends=("nginx")
18makedepends=('tar')
19options=('!strip')
20backup=(
21 "etc/webapps/${_pkgbase}/config.js"
22 "etc/webapps/${_pkgbase}/interface_config.js"
23)
24source=(
25 "https://download.jitsi.org/unstable/jitsi-meet-web_${_version}-1_all.deb"
26 "config_${_version}.deb::https://download.jitsi.org/unstable/jitsi-meet-web-config_${_version}-1_all.deb"
27)
28noextract=(
29 "config_${_version}.deb"
30)
31provides=(${_pkgbase})
32conflicts=(${_pkgbase})
33
34build() {
35 rm -rf ${_pkgbase}
36 mkdir ${_pkgbase}
37 tar xJf data.tar.xz -C ${_pkgbase}
38 ar p "config_${_version}.deb" data.tar.xz | tar xJC ${_pkgbase}
39}
40
41package() {
42 cd "$srcdir/${_pkgbase}"
43
44 DESTDIR="${pkgdir}/usr/share/webapps/${_pkgbase}"
45 CONFDIR="${pkgdir}/etc/webapps/${_pkgbase}"
46 DOCDIR="${pkgdir}/usr/share/doc/${_pkgbase}"
47
48 install -d "$DESTDIR"
49 install -d "$CONFDIR"
50 install -d "$DOCDIR"
51
52 cp -R usr/share/jitsi-meet/* "${DESTDIR}"
53 cp usr/share/jitsi-meet-web-config/config.js "${DESTDIR}"
54 cp -R usr/share/jitsi-meet-web-config/* "${DOCDIR}"
55
56 for i in interface_config.js config.js
57 do
58 install -Dm644 "$DESTDIR/${i}" "$CONFDIR/${i}"
59 ln -sf "/etc/webapps/${_pkgbase}/${i}" "$DESTDIR/${i}"
60 done
61
62 sed -i 's@/usr/share/jitsi-meet@/usr/share/webapps/'${_pkgbase}'@' "${pkgdir}/usr/share/doc/${_pkgbase}/"*
63 sed -i 's@/etc/jitsi/meet@/etc/webapps/'${_pkgbase}'@' "${pkgdir}/usr/share/doc/${_pkgbase}/"*
64
65 chown -R root:root "${pkgdir}"
66}
67sha256sums=('7db4b651ad3125fcc5c742cdf4f61e7323fd536714f5cba6fa9306561fa9a0b9'
68 '520a45c8db60a595e7f08e4d8f36afe567f8c7c93a6d606bd31e252ad1d08a8c')
69

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 13:40:34 Medium 1
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion