mounriver-studio-community
maintainer chenss
· 2 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a source tarball from a non-whitelisted but plausibly project-owned host (file-oss.mounriver.com) for building an official IDE; the content is data and binaries intended for local execution, not remote code injection, and the checksums are verified.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source tarball from a non-whitelisted but plausibly project-owned host (file-oss.mounriver.com) for building an official IDE; the content is data and binaries intended for local execution, not remote code injection, and the checksums are verified.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:21
source=("${pkgname}-${pkgver}.tar.xz::http://file-oss.mounriver.com//upgrade/MounRiver_Studio_Community_Linux_x64_V${pkgver//./}.tar.xz"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Chance Chen <ufbycd@163.com>
2
3
pkgname=mounriver-studio-community
4
pkgver=1.90
5
pkgrel=1
6
arch=('x86_64')
7
pkgdesc="为 Eclipse 平台爱好者提供的一款 RISC-V 内核芯片集成开发环境,支持 WCH 系列 MCU 的工程模板、代码编译、下载、调试等功能。 "
8
url="http://www.mounriver.com"
9
license=('GPL2' 'GPL3' 'custom')
10
provides=()
11
conflicts=()
12
depends=('libftdi-compat' 'libusb' 'hidapi' 'libusb-compat' 'udev')
13
makedepends=()
14
optdepends=('ch34x-dkms-git: CH341SER driver with fixed bug'
15
'i2c-ch341-dkms: CH341 USB-I2C adapter driver'
16
'spi-ch341-usb-dkms: SPI/GPIO driver for CH341'
17
'ch341eepromtool: An i2c serial EEPROM programming tool for the WCH CH341A'
18
'ch341prog-git: A simple command line tool (programmer) interfacing with ch341a'
19
'ch341eeprom-git: A libusb based programming tool for 24xx I²C EEPROMs using the WCH CH341A')
20
options=('!strip')
21
source=("${pkgname}-${pkgver}.tar.xz::http://file-oss.mounriver.com//upgrade/MounRiver_Studio_Community_Linux_x64_V${pkgver//./}.tar.xz"
22
"udev-rules.patch")
23
sha256sums=('11e686fe7d00a861ee8ce9f51e01ba432e73d38e3498bc9d6a27b16af7c70b57'
24
'7ed97c1a494ddbd5b6d594223bc35aa31949c416c0b23a3adabfda239b9f3c73')
25
26
prepare() {
27
cd "$srcdir/MounRiver_Studio_Community_Linux_x64_V${pkgver//./}"
28
patch --forward --strip=1 --input="${srcdir}/udev-rules.patch"
29
find MRS_Community -perm 600 -exec chmod 644 {} \;
30
}
31
32
package() {
33
cd "$srcdir/MounRiver_Studio_Community_Linux_x64_V${pkgver//./}"
34
install -dm0755 "$pkgdir/usr/share/$pkgname"
35
cp -afr MRS_Community/* "$pkgdir/usr/share/$pkgname"
36
37
install -Dm0644 "beforeinstall/50-wch.rules" "${pkgdir}/usr/lib/udev/rules.d/50-wch-community.rules"
38
install -Dm0644 "beforeinstall/60-openocd.rules" "${pkgdir}/usr/lib/udev/rules.d/60-openocd-wch-community.rules"
39
40
install -Dm0755 /dev/stdin "${pkgdir}/usr/bin/openocd-wch-community-arm" << EOF
41
#!/bin/env bash
42
exec /usr/share/$pkgname/toolchain/OpenOCD/bin/openocd -f /usr/share/$pkgname/toolchain/OpenOCD/bin/wch-arm.cfg "\$@"
43
EOF
44
45
install -Dm0755 /dev/stdin "${pkgdir}/usr/bin/openocd-wch-community-riscv" << EOF
46
#!/bin/env bash
47
exec /usr/share/$pkgname/toolchain/OpenOCD/bin/openocd -f /usr/share/$pkgname/toolchain/OpenOCD/bin//wch-riscv.cfg "\$@"
48
EOF
49
50
install -Dm0644 /dev/stdin "${pkgdir}/etc/profile.d/${pkgname}.sh" << EOF
51
[ -d /usr/share/$pkgname/toolchain/arm-none-eabi-gcc/bin/ ] && append_path '/usr/share/$pkgname/toolchain/arm-none-eabi-gcc/bin/'
52
[ -d /usr/share/$pkgname/toolchain/RISC-V\ Embedded\ GCC/bin/ ] && append_path '/usr/share/$pkgname/toolchain/RISC-V\ Embedded GCC/bin/'
53
EOF
54
55
install -Dm755 /dev/stdin "${pkgdir}/usr/bin/${pkgname}" <<EOF
56
#!/bin/sh
57
GDK_BACKEND=x11 /usr/share/$pkgname/MounRiver\ Studio_Community "\$@"
58
EOF
59
60
install -Dm644 /dev/stdin "$pkgdir/usr/share/applications/${pkgname}.desktop" <<EOF
61
[Desktop Entry]
62
Name=MounRiver Studio Community
63
GenericName=MounRiver Studio Community
64
Comment=Eclipse Based Embedded C/C++ IDE for WCH Microcontroller
65
Exec=/usr/bin/$pkgname
66
Icon=/usr/share/$pkgname/icon.xpm
67
Path=/usr/share/$pkgname/
68
Terminal=false
69
StartupNotify=true
70
Type=Application
71
Categories=Development;RISC-V;ARM;
72
EOF
73
}
74
75
# vim: ts=4 sw=4 et
76
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |