nautilus-nutstore

maintainer jeffguorg · 11 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from the official project's CDN (jianguoyun.com), which is plausibly the project's own infrastructure; building from source is normal for AUR packages, and the host, while not whitelisted, is project-specific and not a generic file-sharing service.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the official project's CDN (jianguoyun.com), which is plausibly the project's own infrastructure; building from source is normal for AUR packages, and the host, while not whitelisted, is project-specific and not a generic file-sharing service.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:25 "https://pkg-cdn.jianguoyun.com/static/exe/installer/$pkgver/nutstore_client-$pkgver-linux-src-installer-public.tar.gz"

PKGBUILD

1 offending line(s) highlighted
1#Maintainer: Chao Guo(jeffguorg#gmail.com)
2#Maintainer: Bhoppi Chaw <bhoppi#outlook,com>
3
4pkgname=nautilus-nutstore
5pkgver=6.4.3
6pkgrel=1
7pkgdesc='Nutstore integration for Nautilus'
8arch=(x86_64 aarch64)
9url='https://www.jianguoyun.com/'
10license=('CC-BY-ND-3.0 AND GPL-2.0-or-later')
11depends=(libnautilus-extension)
12optdepends=(nutstore)
13makedepends=(
14 'at-spi2-core'
15 'autoconf'
16 'automake'
17 'gcc'
18 'm4'
19 'make'
20 'libtool'
21 'patch'
22 'pkg-config'
23)
24source=(
25 "https://pkg-cdn.jianguoyun.com/static/exe/installer/$pkgver/nutstore_client-$pkgver-linux-src-installer-public.tar.gz"
26 '00-remove-dependency-from-configure.patch'
27)
28sha256sums=(
29 '8816d91324d2346966e0019981aa6e5df94bb1a016ac5146366dea37d2f4b3ce'
30 '5049f6fb727241f45f2a90061b3f68973a0e29fba43b86f67bbc7ae74de96c94'
31)
32
33prepare() {
34 cd "$srcdir/nutstore_linux_src_installer"
35
36 # Make the GDK dependency check optional
37 patch -p1 <"$srcdir/00-remove-dependency-from-configure.patch"
38
39 # Regenerate the configure script from the patched configure.ac
40 ./update-toolchain.sh
41}
42
43build() {
44 cd "$srcdir/nutstore_linux_src_installer"
45 ./configure || return 1
46 make || return 1
47}
48
49package() {
50 cd "$srcdir/nutstore_linux_src_installer"
51 make DESTDIR="$pkgdir" install
52 install -Dm644 COPYING "$pkgdir/usr/share/licenses/$pkgname/COPYING"
53}
54

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion