lrz-syncshare

LOW
maintainer SaberanMarcross 5 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads the official source tarball and checksum from the LRZ (Leibniz Supercomputing Centre) domain, which is the legitimate provider of the service; despite the static analyzer flagging the host as non-standard, the download is from the project's official infrastructure, and the build process only installs and configures the official software without executing untrusted code or exfiltrating data.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads the official source tarball and checksum from the LRZ (Leibniz Supercomputing Centre) domain, which is the legitimate provider of the service; despite the static analyzer flagging the host as non-standard, the download is from the project's official infrastructure, and the build process only installs and configures the official software without executing untrusted code or exfiltrating data.

2 higher static findings superseded - not the current verdict (shown for transparency)
Medium External download from an untrusted host, not in source=() external_download_not_in_source

curl/wget fetches a URL on a non-allowlisted host that is not part of source=(), so it is not checksum-verified by makepkg.

  • PKGBUILD:14 sha256sums=("$(curl -s https://sasrepo.nas.lrz.de/SHA256SUMS.txt | grep LRZ_Sync_Share_v${pkgver}_Linux.tar.gz | head -n 1 | cut -d ' ' -f 1)")
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("LRZ_Sync_Share_v${pkgver}_Linux.tar.gz::https://tgz.sasrepo.nas.lrz.de/${branch}/LRZ_Sync_Share_v${pkgver}_Linux.tar.gz")

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: André Schamschurko <marcrosssaberan[AT]gmail[DOT]com>
2# Contributer: Andreas Born <futur[DOT]andy[AT]googlemail[DOT]com>
3
4branch=stable
5pkgname=lrz-syncshare
6pkgver=26.3.100
7pkgrel=1
8pkgdesc="Sync client for the LRZ Sync+Share service"
9url='https://syncandshare.lrz.de/'
10arch=('any')
11license=('custom')
12depends=('desktop-file-utils' 'hicolor-icon-theme' 'java-runtime>=15' 'xdg-utils' 'archlinux-java-run')
13source=("LRZ_Sync_Share_v${pkgver}_Linux.tar.gz::https://tgz.sasrepo.nas.lrz.de/${branch}/LRZ_Sync_Share_v${pkgver}_Linux.tar.gz")
14sha256sums=("$(curl -s https://sasrepo.nas.lrz.de/SHA256SUMS.txt | grep LRZ_Sync_Share_v${pkgver}_Linux.tar.gz | head -n 1 | cut -d ' ' -f 1)")
15pkgver() {
16 cat "${srcdir}/LRZ_Sync_Share/VERSION" | sed -e 's/\s*$//'
17}
18
19prepare() {
20 cd "${srcdir}/LRZ_Sync_Share"
21
22 sed -e "s;^CLIENT_INSTALL=.*\$;CLIENT_INSTALL=/usr/share/${pkgname};" \
23 -e 's;^RUN_CMD="$CLIENT_INSTALL/jre/bin/java ;RUN_CMD="/usr/bin/archlinux-java-run -a 15 -- ;' \
24 -i LRZ_Sync_Share-Client.sh
25 sed -e "s;^Icon=.*;Icon=${pkgname};" \
26 -e "s;^Exec=.*;Exec=${pkgname};" -i install-files/LRZ_Sync_Share.desktop
27}
28
29package() {
30 cd "${srcdir}/LRZ_Sync_Share"
31
32 install -Dm755 LRZ_Sync_Share-Client.sh "${pkgdir}/usr/bin/${pkgname}"
33 install -Dm644 LRZ_Sync_Share.jar -t "${pkgdir}/usr/share/${pkgname}/"
34
35 install -Dm644 install-files/LRZ_Sync_Share.desktop "${pkgdir}/usr/share/applications/${pkgname}.desktop"
36 install -Dm644 install-files/LRZ_Sync_Share.png "${pkgdir}/usr/share/icons/hicolor/128x128/apps/${pkgname}.png"
37
38 install -D -m644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
39}
40
41

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 3
2026-09-16 00:03:17 Low 3
2026-09-15 00:25:31 Low 3
2026-09-14 00:27:57 Low 3
2026-09-13 00:19:54 Low 3
2026-09-12 00:25:17 Low 3
2026-09-11 00:19:22 Low 3
2026-09-10 00:22:44 Low 3
2026-09-09 00:04:09 Low 3
2026-09-08 00:18:08 Low 3
2026-09-07 00:30:15 Low 3
2026-09-06 00:17:06 Low 3
2026-09-05 00:16:27 Low 3
2026-09-04 00:03:13 Low 3
2026-09-03 00:15:47 Low 3
2026-09-02 00:02:31 Low 3
2026-09-01 00:11:19 Low 3
2026-08-31 00:19:57 Low 3
2026-08-30 00:04:14 Low 3
2026-08-29 00:29:17 Low 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion