lyrionmusicserver-bin
maintainer FabioLolix
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a prebuilt binary tarball from the project's official community domain (downloads.lms-community.org), which is not on the whitelist but plausibly legitimate; the package installs it without executing remote code or modifying external systems.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt binary tarball from the project's official community domain (downloads.lms-community.org), which is not on the whitelist but plausibly legitimate; the package installs it without executing remote code or modifying external systems.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("https://downloads.lms-community.org/LyrionMusicServer_v${pkgver}/lyrionmusicserver-${pkgver}.tgz"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Fabio 'Lolix' Loli <fabio.loli@disroot.org> -> https://github.com/FabioLolix
2
# Maintainer: Stefan Sielaff <aur AT stefan-sielaff DOT de>
3
4
pkgname=lyrionmusicserver-bin
5
pkgver=9.0.0
6
pkgrel=2
7
pkgdesc="Slimserver for Logitech Squeezebox players. This server is also called Logitech Media Server)"
8
arch=(i686 x86_64 armv7h aarch64)
9
url="https://github.com/LMS-Community/slimserver"
10
license=(GPL-2.0-only)
11
depends=(perl zlib glibc)
12
install=lyrionmusicserver.install
13
options=(!strip)
14
source=("https://downloads.lms-community.org/LyrionMusicServer_v${pkgver}/lyrionmusicserver-${pkgver}.tgz"
15
'lyrionmusicserver-bin.service')
16
sha256sums=('aea9bb5f00bce5b95753c08d4540d87aa396e500375144e81a0c909cb8a8bafa'
17
'f2ea75494d3a24c04189914d0387af7a18359639d8b2ac851c1daf6f731a978c')
18
19
prepare() {
20
cd "lyrionmusicserver-${pkgver}/Bin"
21
rm -rf MSWin32-x86-multi-thread darwin darwin-x86_64 i386-freebsd-64int i86pc-solaris-thread-multi-64int powerpc-linux sparc-linux
22
23
case $CARCH in
24
x86_64) rm -rf {arm,armhf,aarch64,i386}-linux ;;
25
i686) rm -rf {arm,armhf,aarch64,x86_64}-linux ;;
26
aarch64) rm -rf {i386,x86_64,arm,armhf}-linux ;;
27
arm*) rm -rf {i386,x86_64,aarch64}-linux ;;
28
esac
29
}
30
31
package() {
32
install -Dm644 lyrionmusicserver-bin.service -t "${pkgdir}/usr/lib/systemd/system/"
33
34
cd "lyrionmusicserver-${pkgver}"
35
install -d "${pkgdir}"/{opt,usr/share/licenses}/"${pkgname}"
36
ln -s "/opt/${pkgname}/License.txt" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
37
38
# remove old perl modules
39
cd "${srcdir}/lyrionmusicserver-${pkgver}/CPAN/arch"
40
rm -rf {5.10,5.12,5.14,5.16,5.16,5.18,5.20,5.22,5.24,5.26,5.28,5.30,5.32,5.34,5.36,5.38}
41
42
cd "${srcdir}/lyrionmusicserver-${pkgver}"
43
cp -a * "${pkgdir}/opt/${pkgname}"
44
45
mkdir -p "${pkgdir}"/opt/lyrionmusicserver-bin/{cache,Logs,prefs{,/plugin},Plugins}
46
}
47
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |