match
maintainer aksr
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a tarball from the project's official domain (dmitry-kazakov.de), which hosts the software directly; building from this source is normal for AUR packages and poses no inherent risk despite the non-whitelisted host.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's official domain (dmitry-kazakov.de), which hosts the software directly; building from this source is normal for AUR packages and poses no inherent risk despite the non-whitelisted host.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:10
source=("http://www.dmitry-kazakov.de/$pkgname/${pkgname}_${pkgver/./_}.tgz")
PKGBUILD
1 offending line(s) highlighted
1
# Contributor: perlawk
2
# Maintainer: aksr <aksr at t-com dot me>
3
pkgname=match
4
pkgver=1.1
5
pkgrel=2
6
pkgdesc='A powerful tool for syntax analysis, the main idea of pattern matching comes from the SNOBOL4 language.'
7
url='http://www.dmitry-kazakov.de/match/match.htm'
8
arch=('i686' 'x86_64')
9
license=('GPLv3')
10
source=("http://www.dmitry-kazakov.de/$pkgname/${pkgname}_${pkgver/./_}.tgz")
11
md5sums=('cd1de3c51078902034b05d7e8e6c8919')
12
sha1sums=('412bee7e72821be67d7244c933b525b9bf4f6a5b')
13
sha256sums=('9661b18833f6f5c617a0cd99417bcb63cd110822d93da39e651cb12f77620d55')
14
options=(!strip)
15
16
prepare() {
17
cd "${srcdir}/"
18
sed -i '/SILENCE/d;' gcc.mak
19
sed -i 's/-c/-c $(CPPFLAGS) $(CFLAGS)/g' gcc.mak
20
}
21
build() {
22
gcc -fpic -shared match.c -o libmatch.so
23
CFLAGS='-fcommon -fpermissive' make -f gcc.mak
24
}
25
26
package() {
27
cd "${srcdir}/"
28
mkdir -p $pkgdir/usr/{bin,include,share/match,lib}/
29
cp -a match "$pkgdir/usr/bin"
30
cp libmatch.so "$pkgdir/usr/lib/"
31
cp match.h pattern.h patran.h "$pkgdir/usr/include/"
32
cp match.htm *gif *jpg "$pkgdir/usr/share/$pkgname/"
33
}
34
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |