mast

maintainer vali · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from the project's official domain (mast.unican.es), which is not on the whitelist but is plausibly legitimate; building from the project's own source is normal AUR practice and poses low risk.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's official domain (mast.unican.es), which is not on the whitelist but is plausibly legitimate; building from the project's own source is normal AUR practice and poses low risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=('http://mast.unican.es/mast-src-1-5-1-0.tar.gz'

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Johannes Schlatow <johannes.schlatow@googlemail.com>
2
3pkgname=mast
4pkgver=1.5.1.0
5_pkgname=mast-src-1-5-1-0
6pkgrel=1
7pkgdesc="Modeling and Analysis Suite for Real-Time Applications"
8arch=('i686' 'x86_64')
9url="http://mast.unican.es"
10license=('GPL')
11depends=('gtk3'
12 'gtkada')
13source=('http://mast.unican.es/mast-src-1-5-1-0.tar.gz'
14 'xmlada-config')
15md5sums=('6e90388b84c6a92a9f148b8705c73677'
16 '31c59fd5ce1c915a7fc0a83a43949a43')
17
18build() {
19 cd "$srcdir/$_pkgname"
20 sed -i s/xmlada-config/\.\.\\/\.\.\\/\.\.\\/xmlada-config/g mast_xml/compile
21 sed -i s/xmlada-config/\.\.\\/\.\.\\/\.\.\\/xmlada-config/g mast_xml/compile_results
22 ./compile
23}
24
25package() {
26 cd "$srcdir/$_pkgname"
27 mkdir -p $pkgdir/usr/share/{doc/mast,mast,mast_xml}
28 mkdir -p $pkgdir/usr/bin
29
30 cp mast_analysis/mast_analysis $pkgdir/usr/bin
31 cp gmast/src/gmast_analysis $pkgdir/usr/bin
32 cp gmast/gmast $pkgdir/usr/bin
33 cp gmastresults/src/gmastresults $pkgdir/usr/bin
34 cp gmasteditor/src/gmasteditor $pkgdir/usr/bin
35 cp mast_xml/{mast_xml_convert,mast_xml_convert_results} $pkgdir/usr/bin
36 cp pt_editor/src/gmast_pt_editor $pkgdir/usr/bin
37 cp to_mast2/to_mast2 $pkgdir/usr/bin
38
39 cp docs/* $pkgdir/usr/share/doc/mast/
40 chmod +r $pkgdir/usr/share/doc/mast/*
41 cp -r examples $pkgdir/usr/share/mast/
42 chmod +r $pkgdir/usr/share/mast/examples/*
43 cp README.txt $pkgdir/usr/share/mast/
44 cp mast_xml/README.txt $pkgdir/usr/share/mast_xml
45 cp mast-status.txt $pkgdir/usr/share/mast/
46}
47

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion