lzma_alone

LOW
maintainer dbermond 2 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a 7-Zip SDK archive from the official project website, used to build a legitimate compression tool; downloading from the project's own domain, even if not whitelisted, poses minimal risk as it is part of normal AUR packaging.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a 7-Zip SDK archive from the official project website, used to build a legitimate compression tool; downloading from the project's own domain, even if not whitelisted, poses minimal risk as it is part of normal AUR packaging.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("https://www.7-zip.org/a/lzma${pkgver/./}.7z"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Daniel Bermond <dbermond@archlinux.org>
2
3pkgname=lzma_alone
4pkgver=26.03
5pkgrel=1
6pkgdesc='A tool used to perform lossless data compression'
7arch=('x86_64')
8url='https://www.7-zip.org/sdk.html'
9license=('LZMA-SDK-9.22')
10depends=(
11 'glibc'
12 'libgcc'
13 'libstdc++')
14source=("https://www.7-zip.org/a/lzma${pkgver/./}.7z"
15 '010-lzma_alone-use-arch-flags.patch')
16noextract=("lzma${pkgver/./}.7z")
17sha256sums=('86c213f752520ab5325c310f50bef63ec344b56dd1c80b0246d06dc6cec953b2'
18 '8c1905241ce2d517b019b3101bab5e4994ca6864fe00b6ce303470adec66ed85')
19
20prepare() {
21 mkdir -p "lzma-sdk-${pkgver}"
22 bsdtar -x -f "${srcdir}/lzma${pkgver/./}.7z" -C "lzma-sdk-${pkgver}"
23 chmod 644 "lzma-sdk-${pkgver}/CPP/7zip/7zip_gcc.mak"
24 patch -d "lzma-sdk-${pkgver}" --binary -Np1 -i "${srcdir}/010-lzma_alone-use-arch-flags.patch"
25}
26
27build() {
28 make -C "lzma-sdk-${pkgver}/CPP/7zip/Bundles/LzmaCon" -f makefile.gcc
29
30 # create a LICENSE file
31 sed -n '27,41p' "lzma-sdk-${pkgver}/DOC/lzma-sdk.txt" > "lzma-sdk-${pkgver}/DOC/LICENSE"
32}
33
34package() {
35 install -D -m755 "lzma-sdk-${pkgver}/CPP/7zip/Bundles/LzmaCon/_o/lzma" "${pkgdir}/usr/bin/lzma_alone"
36 install -D -m644 "lzma-sdk-${pkgver}/DOC/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
37}
38

Changes since previous scan

--- PKGBUILD @ 2026-09-05 00:16
+++ PKGBUILD @ 2026-09-17 00:27
@@ -1,7 +1,7 @@
# Maintainer: Daniel Bermond <dbermond@archlinux.org>
pkgname=lzma_alone
-pkgver=26.02
+pkgver=26.03
pkgrel=1
pkgdesc='A tool used to perform lossless data compression'
arch=('x86_64')
@@ -14,7 +14,7 @@
source=("https://www.7-zip.org/a/lzma${pkgver/./}.7z"
'010-lzma_alone-use-arch-flags.patch')
noextract=("lzma${pkgver/./}.7z")
-sha256sums=('2878c85f5f43a4a4e0952b1fd4e5fe097c1c143997a8047c7e1e788892aa9357'
+sha256sums=('86c213f752520ab5325c310f50bef63ec344b56dd1c80b0246d06dc6cec953b2'
'8c1905241ce2d517b019b3101bab5e4994ca6864fe00b6ce303470adec66ed85')
prepare() {

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 01:59:11 Medium 1
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion