libreswan
The source URL is hosted on the project's official domain (download.libreswan.org), which is a standard and trusted location for the software, despite not being on the analyzer's whitelist; the package builds from official source code and poses no execution or supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source URL is hosted on the project's official domain (download.libreswan.org), which is a standard and trusted location for the software, despite not being on the analyzer's whitelist; the package builds from official source code and poses no execution or supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:27
"https://download.libreswan.org/${pkgname}-${pkgver}.tar.gz"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Cedric Roijakkers <cedric at roijakkers dot be>.
# Based on previous work from the following people:
# Contributor: Chris Severance <aur.severach at spamgourmet dot com>
# Contributor: Gomasy <nyan at gomasy dot jp>
# Contributor: Alexandre BIQUE <bique.alexandre at gmail dot com>
# Contributor: Patrick Burroughs (Celti) <celti at celti dot name>
set -u
pkgname='libreswan'
pkgver='5.4'
pkgrel='1'
pkgdesc='IPsec implementation with IKEv1 and IKEv2 keying protocols'
arch=('x86_64' 'armv7h' 'aarch64')
url='https://libreswan.org/'
license=('GPL-2.0-or-later')
depends=('systemd' 'nss' 'libcap-ng' 'curl' 'inetutils' 'audit' 'nspr' 'pam' 'libxcrypt' 'libevent')
optdepends=(
'networkmanager-libreswan: NetworkManager support'
'networkmanager-l2tp: L2TP support for NetworkManager using libreswan for IPSec'
)
makedepends=('docbook-xsl' 'xmlto' 'flex' 'bison')
conflicts=('freeswan' 'openswan' 'strongswan' 'ipsec-tools')
backup=('etc/ipsec.conf' 'etc/ipsec.secrets' 'etc/pam.d/pluto')
install="${pkgname}.install"
_srcdir="${pkgname}-${pkgver}"
source=(
"https://download.libreswan.org/${pkgname}-${pkgver}.tar.gz"
'tmpfiles.conf'
'libreswan.install'
)
sha256sums=('d26340cf625316cc9127e05b392214a24a10889f4f1d9940c2ea64bab710a855'
'78265c690d58228c3bcc1a8793456172c39d493d268e9d9b1816288d0a47f573'
'762be0c8e1df04bcd94776d19b669bbc20754e19cae7c73a2d45fdc370fa4b32')
# https://git.centos.org/rpms/libreswan/blob/c8s/f/SPECS/libreswan.spec
_bargs=(
LIBEXECDIR='/usr/lib/ipsec'
#INC_MANDIR='/usr/share/man'
MANDIR='/usr/share/man'
SBINDIR='/usr/bin'
#INC_USRLOCAL='/usr' # required by 3.32 for /usr/share/doc
PREFIX='/usr'
USE_DNSSEC=false
USE_LABELED_IPSEC=false
USE_LIBCAP_NG=true
USE_DH2=false # insecure modp1024; broken in 5.4, see https://github.com/libreswan/libreswan/issues/2980
USE_LEAK_DETECTIVE=false
USE_XAUTH=true
)
prepare() {
set -u
bash -n "${srcdir}/${install}"
set +u
}
build() {
set -u
cd "${_srcdir}"
# Disable preprocessor warnings, because the build failed with GCC 13.2
local _cf=(
-Wp,-w
)
CFLAGS="${CFLAGS} ${_cf[*]}" \
nice make -s "${_bargs[@]}" programs
set +u
}
package() {
set -u
cd "${_srcdir}"
make -j1 DESTDIR="${pkgdir}/" "${_bargs[@]}" install
#sed -e '1s|python\b|python2|' -i "${pkgdir}/usr/lib/ipsec"/{verify,show}
install -Dpm644 "${srcdir}/tmpfiles.conf" "${pkgdir}/usr/lib/tmpfiles.d/libreswan.conf"
rm -rf "${pkgdir}/var"
install -Dpm644 <(cat << EOF
# Automatically generated by ${pkgname}-${pkgver} PKGBUILD from Arch Linux AUR
# https://aur.archlinux.org/
# Disable redirects for ipsec tunnels
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.default.send_redirects = 0
EOF
) "${pkgdir}/usr/lib/sysctl.d/${pkgname}-icmp-redirects.conf"
install -Dm644 <(sed -e 's: = 0: = 1:g' "${pkgdir}/usr/lib/sysctl.d/${pkgname}-icmp-redirects.conf") "${pkgdir}/usr/lib/${pkgname}/icmp-redirects.conf.revert"
if [ "$(vercmp "${pkgver}" '4.0')" -ge 0 ]; then
install -dm700 "${pkgdir}/var/lib/ipsec/nss"
fi
set +u
}
set +u
# vim:set ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |