libosmocore

LOW
maintainer fixeria 19 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a tarball from the project's official release infrastructure (downloads.osmocom.org), which is a plausibly legitimate host for the project, despite not being on a standard whitelist; building from official project sources is normal AUR packaging behavior.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's official release infrastructure (downloads.osmocom.org), which is a plausibly legitimate host for the project, despite not being on a standard whitelist; building from official project sources is normal AUR packaging behavior.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:27 source=("https://downloads.osmocom.org/releases/${pkgname}/${pkgname}-${pkgver}.tar.bz2")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Vadim Yanitskiy <fixeria@osmocom.org>
2# Contributor: Matt Johnson <matt9j@cs.washington.edu>
3# Contributor: Dominik Heidler <dominik@heidler.eu>
4# Contributor: Denis 'GNUtoo' Carikli <GNUtoo@cyberdimension.org>
5
6pkgname=libosmocore
7pkgver=1.14.2
8pkgrel=1
9pkgdesc="Osmocom core libraries"
10arch=('armv7h' 'i686' 'x86_64')
11url="https://osmocom.org/projects/libosmocore/"
12license=('GPL-2.0-or-later')
13groups=()
14conflicts=("${pkgname}-git")
15provides=('libosmocodec.so=4-64'
16 'libosmocoding.so=0-64'
17 'libosmocore.so=22-64'
18 'libosmoctrl.so=0-64'
19 'libosmogb.so=14-64'
20 'libosmogsm.so=20-64'
21 'libosmoisdn.so=0-64'
22 'libosmosim.so=2-64'
23 'libosmousb.so=0-64'
24 'libosmovty.so=13-64')
25depends=('pcsclite' 'talloc' 'libusb' 'lksctp-tools' 'libmnl' 'gnutls' 'systemd-libs' 'liburing')
26makedepends=('python')
27source=("https://downloads.osmocom.org/releases/${pkgname}/${pkgname}-${pkgver}.tar.bz2")
28sha256sums=('9c029a1f5bb617e86b3278df3dad3af732a5ce0bc9427b4012ff7d813d708b65')
29
30build() {
31 cd "${srcdir}/${pkgname}-${pkgver}"
32 ./configure --prefix=/usr \
33 --exec-prefix=/usr \
34 --bindir=/usr/bin \
35 --sbindir=/usr/bin \
36 --datadir=/usr/share \
37 --libexecdir=/usr/lib \
38 --localstatedir=/var \
39 --docdir=/usr/share/doc/libosmocore \
40 --libdir=/usr/lib/ \
41 --enable-systemd-logging
42 make
43}
44
45check() {
46 cd "${srcdir}/${pkgname}-${pkgver}"
47 make check
48}
49
50package() {
51 cd "${srcdir}/${pkgname}-${pkgver}"
52 make DESTDIR=$pkgdir install
53}
54
55# vim:set ts=2 sw=2 et:
56

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion