mast

LOW
maintainer vali 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a tarball from the project's official domain (mast.unican.es), which is not on the whitelist but is plausibly legitimate; building from the project's own source is normal AUR practice and poses low risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's official domain (mast.unican.es), which is not on the whitelist but is plausibly legitimate; building from the project's own source is normal AUR practice and poses low risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=('http://mast.unican.es/mast-src-1-5-1-0.tar.gz'

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Johannes Schlatow <johannes.schlatow@googlemail.com>
2
3pkgname=mast
4pkgver=1.5.1.0
5_pkgname=mast-src-1-5-1-0
6pkgrel=1
7pkgdesc="Modeling and Analysis Suite for Real-Time Applications"
8arch=('i686' 'x86_64')
9url="http://mast.unican.es"
10license=('GPL')
11depends=('gtk3'
12 'gtkada')
13source=('http://mast.unican.es/mast-src-1-5-1-0.tar.gz'
14 'xmlada-config')
15md5sums=('6e90388b84c6a92a9f148b8705c73677'
16 '31c59fd5ce1c915a7fc0a83a43949a43')
17
18build() {
19 cd "$srcdir/$_pkgname"
20 sed -i s/xmlada-config/\.\.\\/\.\.\\/\.\.\\/xmlada-config/g mast_xml/compile
21 sed -i s/xmlada-config/\.\.\\/\.\.\\/\.\.\\/xmlada-config/g mast_xml/compile_results
22 ./compile
23}
24
25package() {
26 cd "$srcdir/$_pkgname"
27 mkdir -p $pkgdir/usr/share/{doc/mast,mast,mast_xml}
28 mkdir -p $pkgdir/usr/bin
29
30 cp mast_analysis/mast_analysis $pkgdir/usr/bin
31 cp gmast/src/gmast_analysis $pkgdir/usr/bin
32 cp gmast/gmast $pkgdir/usr/bin
33 cp gmastresults/src/gmastresults $pkgdir/usr/bin
34 cp gmasteditor/src/gmasteditor $pkgdir/usr/bin
35 cp mast_xml/{mast_xml_convert,mast_xml_convert_results} $pkgdir/usr/bin
36 cp pt_editor/src/gmast_pt_editor $pkgdir/usr/bin
37 cp to_mast2/to_mast2 $pkgdir/usr/bin
38
39 cp docs/* $pkgdir/usr/share/doc/mast/
40 chmod +r $pkgdir/usr/share/doc/mast/*
41 cp -r examples $pkgdir/usr/share/mast/
42 chmod +r $pkgdir/usr/share/mast/examples/*
43 cp README.txt $pkgdir/usr/share/mast/
44 cp mast_xml/README.txt $pkgdir/usr/share/mast_xml
45 cp mast-status.txt $pkgdir/usr/share/mast/
46}
47

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion