nautilus-nutstore
maintainer jeffguorg
· 11 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a tarball from the official project's CDN (jianguoyun.com), which is plausibly the project's own infrastructure; building from source is normal for AUR packages, and the host, while not whitelisted, is project-specific and not a generic file-sharing service.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the official project's CDN (jianguoyun.com), which is plausibly the project's own infrastructure; building from source is normal for AUR packages, and the host, while not whitelisted, is project-specific and not a generic file-sharing service.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:25
"https://pkg-cdn.jianguoyun.com/static/exe/installer/$pkgver/nutstore_client-$pkgver-linux-src-installer-public.tar.gz"
PKGBUILD
1 offending line(s) highlighted
1
#Maintainer: Chao Guo(jeffguorg#gmail.com)
2
#Maintainer: Bhoppi Chaw <bhoppi#outlook,com>
3
4
pkgname=nautilus-nutstore
5
pkgver=6.4.3
6
pkgrel=1
7
pkgdesc='Nutstore integration for Nautilus'
8
arch=(x86_64 aarch64)
9
url='https://www.jianguoyun.com/'
10
license=('CC-BY-ND-3.0 AND GPL-2.0-or-later')
11
depends=(libnautilus-extension)
12
optdepends=(nutstore)
13
makedepends=(
14
'at-spi2-core'
15
'autoconf'
16
'automake'
17
'gcc'
18
'm4'
19
'make'
20
'libtool'
21
'patch'
22
'pkg-config'
23
)
24
source=(
25
"https://pkg-cdn.jianguoyun.com/static/exe/installer/$pkgver/nutstore_client-$pkgver-linux-src-installer-public.tar.gz"
26
'00-remove-dependency-from-configure.patch'
27
)
28
sha256sums=(
29
'8816d91324d2346966e0019981aa6e5df94bb1a016ac5146366dea37d2f4b3ce'
30
'5049f6fb727241f45f2a90061b3f68973a0e29fba43b86f67bbc7ae74de96c94'
31
)
32
33
prepare() {
34
cd "$srcdir/nutstore_linux_src_installer"
35
36
# Make the GDK dependency check optional
37
patch -p1 <"$srcdir/00-remove-dependency-from-configure.patch"
38
39
# Regenerate the configure script from the patched configure.ac
40
./update-toolchain.sh
41
}
42
43
build() {
44
cd "$srcdir/nutstore_linux_src_installer"
45
./configure || return 1
46
make || return 1
47
}
48
49
package() {
50
cd "$srcdir/nutstore_linux_src_installer"
51
make DESTDIR="$pkgdir" install
52
install -Dm644 COPYING "$pkgdir/usr/share/licenses/$pkgname/COPYING"
53
}
54
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |