mailfromd

LOW
maintainer k0ste 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a legitimate tarball from a project-maintained GNU mirror (download.gnu.org.ua), which is not whitelisted but plausibly official; building from source is normal AUR practice and poses low risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a legitimate tarball from a project-maintained GNU mirror (download.gnu.org.ua), which is not whitelisted but plausibly official; building from source is normal AUR practice and poses low risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 "ftp://download.gnu.org.ua/pub/release/${pkgname}/${pkgname}-${pkgver}.tar.xz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Konstantin Shalygin <k0ste@k0ste.ru>
2# Contributor: Konstantin Shalygin <k0ste@k0ste.ru>
3
4pkgname='mailfromd'
5pkgver='8.7'
6pkgrel='1'
7pkgdesc='General-Purpose Mail Filter'
8arch=('x86_64')
9url="http://puszcza.gnu.org.ua/software/${pkgname}"
10depends=('smtp-server' 'gdbm' 'mailutils' 'geoip' 'adns')
11makedepends=('mailutils')
12license=('GPL')
13source=("${pkgname}.service"
14 "ftp://download.gnu.org.ua/pub/release/${pkgname}/${pkgname}-${pkgver}.tar.xz")
15sha256sums=('26a380c1bfe964c1aaaf351f85504c72ca7be5dca199e7cd79252c83382a9ce0'
16 'd82a4a8160c937871c5d9b147b760365c09026753ffbeed09c5a35b2ac278e51')
17backup=('etc/mailfromd.mf')
18
19prepare() {
20 cd "${pkgname}-${pkgver}"
21 ./configure \
22 --prefix=/usr \
23 --sbindir=/usr/bin \
24 --bindir=/usr/bin \
25 --sysconfdir=/etc \
26 --localstatedir=/var/lib \
27 --with-gdbm \
28 --with-geoip \
29 --enable-ipv6 \
30 --enable-syslog-async \
31 DEFAULT_USER=mail \
32 DEFAULT_SOCKET=inet:8890@localhost \
33 DEFAULT_LOG_FACILITY=mail
34}
35
36build() {
37 cd "${srcdir}/${pkgname}-${pkgver}"
38 make
39}
40
41check() {
42 cd "${srcdir}/${pkgname}-${pkgver}/tests"
43 ./testsuite -e --color=always
44}
45
46package() {
47 cd "${srcdir}/${pkgname}-${pkgver}"
48 make DESTDIR="${pkgdir}" install
49 install -dm770 -o 8 -g 12 "${pkgdir}/var/lib/${pkgname}"
50 install -Dm644 "${srcdir}/${pkgname}.service" "${pkgdir}/usr/lib/systemd/system/${pkgname}.service"
51}
52

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion