leet-plugins

maintainer Rhinoceros · 19 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from Google's archived project hosting, which is a non-standard host but plausibly the project's official release location; the package builds from source and installs compiled LADSPA plugins, posing low risk as the source is verifiable via checksum and not executable code from an untrusted third party.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from Google's archived project hosting, which is a non-standard host but plausibly the project's official release location; the package builds from source and installs compiled LADSPA plugins, posing low risk as the source is verifiable via checksum and not executable code from an untrusted third party.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/leetplugins/${_pkgname}-${pkgver}.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Rhinoceros <https://aur.archlinux.org/account/rhinoceros>
2# Contributor: Daniel Stumpner <bigstumpi@gmx.de>
3# Contributor: SpepS <dreamspepser at yahoo dot it>
4
5pkgname=leet-plugins
6_pkgname=LEET-plugins
7pkgver=0.2
8pkgrel=2
9pkgdesc='LADSPA plugins especially for use with Ardour'
10arch=('i686' 'x86_64')
11url='http://code.google.com/p/leetplugins/'
12license=('GPL-2.0-or-later')
13depends=('gcc-libs')
14source=("https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/leetplugins/${_pkgname}-${pkgver}.tar.gz")
15sha256sums=('e2868cffe65a6fc4f7325ef1fb3831e1530718c75aa28c9cbb44f4399e5059a1')
16
17build() {
18 cd ${_pkgname}-${pkgver}
19 make all
20}
21
22package() {
23 cd ${_pkgname}-${pkgver}
24 install -Dm 755 LEET_chorus.so ${pkgdir}/usr/lib/ladspa/LEET_chorus.so
25 install -Dm 755 LEET_eqbw2x2_1.so ${pkgdir}/usr/lib/ladspa/LEET_eqbw2x2_1.so
26 install -Dm 755 LEET_eqbw2x2.so ${pkgdir}/usr/lib/ladspa/LEET_eqbw2x2.so
27}
28

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion