mailfromd

maintainer k0ste · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a legitimate tarball from a project-maintained GNU mirror (download.gnu.org.ua), which is not whitelisted but plausibly official; building from source is normal AUR practice and poses low risk.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a legitimate tarball from a project-maintained GNU mirror (download.gnu.org.ua), which is not whitelisted but plausibly official; building from source is normal AUR practice and poses low risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 "ftp://download.gnu.org.ua/pub/release/${pkgname}/${pkgname}-${pkgver}.tar.xz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Konstantin Shalygin <k0ste@k0ste.ru>
2# Contributor: Konstantin Shalygin <k0ste@k0ste.ru>
3
4pkgname='mailfromd'
5pkgver='8.7'
6pkgrel='1'
7pkgdesc='General-Purpose Mail Filter'
8arch=('x86_64')
9url="http://puszcza.gnu.org.ua/software/${pkgname}"
10depends=('smtp-server' 'gdbm' 'mailutils' 'geoip' 'adns')
11makedepends=('mailutils')
12license=('GPL')
13source=("${pkgname}.service"
14 "ftp://download.gnu.org.ua/pub/release/${pkgname}/${pkgname}-${pkgver}.tar.xz")
15sha256sums=('26a380c1bfe964c1aaaf351f85504c72ca7be5dca199e7cd79252c83382a9ce0'
16 'd82a4a8160c937871c5d9b147b760365c09026753ffbeed09c5a35b2ac278e51')
17backup=('etc/mailfromd.mf')
18
19prepare() {
20 cd "${pkgname}-${pkgver}"
21 ./configure \
22 --prefix=/usr \
23 --sbindir=/usr/bin \
24 --bindir=/usr/bin \
25 --sysconfdir=/etc \
26 --localstatedir=/var/lib \
27 --with-gdbm \
28 --with-geoip \
29 --enable-ipv6 \
30 --enable-syslog-async \
31 DEFAULT_USER=mail \
32 DEFAULT_SOCKET=inet:8890@localhost \
33 DEFAULT_LOG_FACILITY=mail
34}
35
36build() {
37 cd "${srcdir}/${pkgname}-${pkgver}"
38 make
39}
40
41check() {
42 cd "${srcdir}/${pkgname}-${pkgver}/tests"
43 ./testsuite -e --color=always
44}
45
46package() {
47 cd "${srcdir}/${pkgname}-${pkgver}"
48 make DESTDIR="${pkgdir}" install
49 install -dm770 -o 8 -g 12 "${pkgdir}/var/lib/${pkgname}"
50 install -Dm644 "${srcdir}/${pkgname}.service" "${pkgdir}/usr/lib/systemd/system/${pkgname}.service"
51}
52

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion