jrebel
maintainer stick
· 6 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a source tarball from a plausibly official vendor host (dl.zeroturnaround.com) for a legitimate tool; the host is not whitelisted but is associated with the software vendor, and the content is verified via sha256sum.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source tarball from a plausibly official vendor host (dl.zeroturnaround.com) for a legitimate tool; the host is not whitelisted but is associated with the software vendor, and the content is verified via sha256sum.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
source=("https://dl.zeroturnaround.com/jrebel/releases/$pkgname-$pkgver-nosetup.zip"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Stick <stick at stma dot is>
2
# shellcheck disable=2034
3
4
pkgname=jrebel
5
pkgver=2020.1.1
6
pkgrel=1
7
pkgdesc="Reload code changes instantly"
8
url="http://jrebel.com/software/jrebel/"
9
license=('custom')
10
arch=('i686' 'x86_64')
11
provides=('jrebel')
12
depends=('java-environment')
13
optdepends=('lib32-glibc: 32-bit support')
14
backup=('etc/profile.d/jrebel.sh'
15
'etc/profile.d/jrebel.csh')
16
install=jrebel.install
17
18
source=("https://dl.zeroturnaround.com/jrebel/releases/$pkgname-$pkgver-nosetup.zip"
19
"$pkgname.csh"
20
"$pkgname.install"
21
"$pkgname.sh")
22
23
sha256sums=('53f768793342228ffbbb868857cd018808b9749328e02e971b9293ab6fd4a0c5'
24
'7dbc38b6bfc45a037620bd8a21583e00308d53311285c98215b660efdb007431'
25
'6aab55f31601000e1f21ba6d42ecd363d55839a258ba5e489c7041f9b909d128'
26
'd1a5193a071eeedb4d5e96a0eb90aaa4f7daad0cdfbe54ff9c89967c50634635')
27
28
package() {
29
echo "Creating required directories"
30
# shellcheck disable=2154
31
mkdir -p "$pkgdir"/{opt/$pkgname,/etc/profile.d,usr/share/licenses/$pkgname}
32
33
# shellcheck disable=2154
34
cd "$srcdir/$pkgname" || exit
35
36
echo "Removing .cmd files"
37
rm bin/*.cmd
38
39
echo "Installing licenses, scripts, and readme"
40
mv 3rd-party-licenses-jrebel.txt License.txt readme.txt "$pkgdir/usr/share/licenses/$pkgname/"
41
mv ./* "$pkgdir/opt/$pkgname"
42
cd "$srcdir" || exit
43
install -m755 $pkgname.{c,}sh "$pkgdir/etc/profile.d/"
44
}
45
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |