matlab-mpm

LOW
maintainer vitaliikuzhdin 6 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads a prebuilt binary from mathworks.com (a trusted vendor domain) for installation, which is normal for official binaries; the source URL uses a GitHub mirror for versioning metadata, which is non-executable and used only for pkgver computation.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt binary from mathworks.com (a trusted vendor domain) for installation, which is normal for official binaries; the source URL uses a GitHub mirror for versioning metadata, which is non-executable and used only for pkgver computation.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:41 "${pkgname}-${_pkgver}-x86_64::https://ssd.mathworks.com/supportfiles/downloads/${_name}/${_pkgver}/glnxa64/${_name}"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Vitalii Kuzhdin <vitaliikuzhdin@gmail.com>
2
3_name="mpm"
4pkgname="matlab-${_name}"
5_commit="6042363c84ac9ebee96467d5dd11e290a8f5a801"
6pkgver=2026.7+r157.g6042363
7_pkgver="${pkgver%+*}"
8pkgrel=1
9epoch=1
10pkgdesc="MATLAB Package Manager"
11arch=(
12 'x86_64' # glnxa64
13)
14url="https://www.mathworks.com/products/mpm.html"
15_url="https://github.com/mathworks-ref-arch/matlab-dockerfile"
16license=(
17 'custom:MATLAB EULA'
18)
19depends=(
20 'glibc'
21
22 # https://www.mathworks.com/help/install/ug/get-mpm-os-command-line.html
23 'ca-certificates'
24 'unzip'
25
26 # https://github.com/mathworks-ref-arch/container-images/commit/ea7154f8f2b3efa2bcbaded5ba151285a0281c2e
27 # https://github.com/mathworks-ref-arch/matlab-dockerfile/issues/160
28 'libatomic'
29)
30makedepends=(
31 'git'
32)
33optdepends=(
34 "${pkgname}-input: input files used with '--inputfile'"
35)
36_pkgsrc="${_url##*/}"
37source=(
38 "${_pkgsrc}::git+${_url}.git#commit=${_commit}"
39)
40source_x86_64=(
41 "${pkgname}-${_pkgver}-x86_64::https://ssd.mathworks.com/supportfiles/downloads/${_name}/${_pkgver}/glnxa64/${_name}"
42)
43sha256sums=('f3d858660aaf294e9e7d844b1940a1dbbe8cfc46502845382afaf8f5292de312')
44sha256sums_x86_64=('cdd1062dc8d30de2103ebf8713cb1935d732db6d90a69718e0d49616325f3fef')
45
46prepare() {
47 # comment out after updating _commit
48 if [[ "${pkgver}" == "${_pkgver}+r0.updateme" ]]; then
49 echo " -> ERROR: Maitainer, please update the git commit hash!"
50 exit 1
51 fi
52}
53
54pkgver() {
55 cd "${srcdir}/${_pkgsrc}"
56 printf '%s+r%s.g%s' "${_pkgver}" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
57}
58
59package() {
60 cd "${srcdir}"
61 install -vDm755 "${pkgname}-${_pkgver}-${CARCH}" "${pkgdir}/usr/bin/${pkgname}"
62
63 cd "${_pkgsrc}"
64 install -vDm644 "MPM.md" "${pkgdir}/usr/share/doc/${pkgname}/README.md"
65 install -vDm644 "LICENSE.md" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.md"
66
67 # https://kdeldycke.github.io/meta-package-manager/
68 # ln -vsf "${pkgname}" "${pkgdir}/usr/bin/${_name}"
69}
70

Changes since previous scan

--- PKGBUILD @ 2026-09-25 00:03
+++ PKGBUILD @ 2026-10-02 00:00
@@ -2,8 +2,8 @@
_name="mpm"
pkgname="matlab-${_name}"
-_commit="77fec96ac0eced0a65083eefe93482f11b4d12d7"
-pkgver=2026.6+r156.g77fec96
+_commit="6042363c84ac9ebee96467d5dd11e290a8f5a801"
+pkgver=2026.7+r157.g6042363
_pkgver="${pkgver%+*}"
pkgrel=1
epoch=1
@@ -40,8 +40,8 @@
source_x86_64=(
"${pkgname}-${_pkgver}-x86_64::https://ssd.mathworks.com/supportfiles/downloads/${_name}/${_pkgver}/glnxa64/${_name}"
)
-sha256sums=('073d5f0163679bac1de0326f26bc1b890e8610f53d3511ac7c4ff6bc8f9a530b')
-sha256sums_x86_64=('e8442d253046d154c4dcc5ead7338369a28fcaf4ee8f171992fc4eb63c65ca4d')
+sha256sums=('f3d858660aaf294e9e7d844b1940a1dbbe8cfc46502845382afaf8f5292de312')
+sha256sums_x86_64=('cdd1062dc8d30de2103ebf8713cb1935d732db6d90a69718e0d49616325f3fef')
prepare() {
# comment out after updating _commit

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 11:11:47 Medium 1
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 17:23:26 Medium 1
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion