mojo-ide
maintainer orphaned
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a source tarball from the project's official domain (embeddedmicro.com), which is plausibly the project's own release infrastructure; the download is of a prebuilt binary IDE, but the host is official and checksummed, making it a normal AUR package with low risk despite the non-whitelisted host flag.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The package downloads a source tarball from the project's official domain (embeddedmicro.com), which is plausibly the project's own release infrastructure; the download is of a prebuilt binary IDE, but the host is official and checksummed, making it a normal AUR package with low risk despite the non-whitelisted host flag.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
source=("https://embeddedmicro.com/ide/$pkgname-$pkgver-linux64.tgz"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Jonathan la Cour <jon@lacour.me>
2
pkgname=mojo-ide
3
pkgver=B1.3.6
4
pkgrel=1
5
pkgdesc="The IDE for Mojo"
6
arch=('x86_64')
7
url="https://embeddedmicro.com/"
8
license=('unknown')
9
groups=()
10
depends=('java-environment' 'sh' 'bash')
11
optdepends=()
12
provides=()
13
conflicts=()
14
replaces=()
15
source=("https://embeddedmicro.com/ide/$pkgname-$pkgver-linux64.tgz"
16
"mojo-ide.desktop"
17
"run-mojo-ide.sh")
18
sha512sums=("7d3af890e29225ccd47e9f8c5720f071fe10d7fc62e075812f061e4727c4fb0320f8349915fc07a3f0ec199b7f5ab3d518dcf6de92fe92670b979b5fa29066f5"
19
"ed041393bd96b6522a43ddc90877d9fcd6f9ebce0ea5271746508d2d7434a8d8cadf267f589d034f85edabe2d108a86fd953b9a401fd2b026aeaa85c4c5db006"
20
"80aa2594e159fdee6f765ca0394a9f811664bc620c123601dc2d4b1f40c0786d40137ebe360a74eae398556803d492ef40b1cb037cbd0e83c31e0d3a21c6e200")
21
22
package() {
23
cd "$srcdir/$pkgname-$pkgver"
24
25
if [ ! -f "/usr/lib/udev/rules.d/99-mojo.rules" ]; then
26
install -Dm 644 "driver/99-mojo.rules" "$pkgdir/usr/lib/udev/rules.d/99-mojo.rules"
27
fi
28
29
install -Dm 755 "$srcdir/run-mojo-ide.sh" "$pkgdir/usr/bin/mojo-ide"
30
install -Dm 644 "$srcdir/mojo-ide.desktop" "$pkgdir/usr/share/applications/mojo-ide.desktop"
31
32
mkdir -p "$pkgdir/opt"
33
cp -R "$srcdir/$pkgname-$pkgver/" "$pkgdir/opt/"
34
mv "$pkgdir/opt/$pkgname-$pkgver" "$pkgdir/opt/$pkgname"
35
}
36
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |