ni-daqmx-base-bin
The package downloads a prebuilt ISO from download.ni.com, which is National Instruments' (now NI/Emerson) official software distribution domain — this is the legitimate vendor host for NI-DAQmx Base. The ISO contains RPMs that are extracted and installed under /opt. While the host is the official NI download server (not a personal or unofficial host), the package installs prebuilt binary RPMs without source code, and the extraction logic is somewhat sloppy (cp -a * copies everything including leftover artifacts). The sha256sum is present and pinned. The main concern is that binary-only driver software from a closed-source vendor is being extracted and placed under /opt without any integrity verification of individual RPMs beyond the ISO checksum. This is a legitimate medium-risk supply-chain concern: executed binary code from a closed-source vendor with no source verification, though the host itself is the official NI distribution server. Not high because there is no evidence of malice, obfuscation, or unofficial hosting.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("${pkgname}-${pkgver}.iso::https://download.ni.com/support/softlib/multifunction_daq/nidaqmxbase/${pkgver%.*}/linux/nidaqmxbase-${pkgver}.iso")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The package downloads a prebuilt ISO from download.ni.com, which is National Instruments' (now NI/Emerson) official software distribution domain — this is the legitimate vendor host for NI-DAQmx Base. The ISO contains RPMs that are extracted and installed under /opt. While the host is the official NI download server (not a personal or unofficial host), the package installs prebuilt binary RPMs without source code, and the extraction logic is somewhat sloppy (cp -a * copies everything including leftover artifacts). The sha256sum is present and pinned. The main concern is that binary-only driver software from a closed-source vendor is being extracted and placed under /opt without any integrity verification of individual RPMs beyond the ISO checksum. This is a legitimate medium-risk supply-chain concern: executed binary code from a closed-source vendor with no source verification, though the host itself is the official NI distribution server. Not high because there is no evidence of malice, obfuscation, or unofficial hosting.
PKGBUILD
1 offending line(s) highlightedpkgname=ni-daqmx-base-bin
pkgver=15.0.0
pkgrel=1
pkgdesc="a subset of NI-DAQmx functionality for your data acquisition system"
arch=(x86_64)
url="https://www.ni.com/en-gb/support/downloads/drivers/download.ni-daqmx-base.html#326057"
license=(custom)
depends=(
)
makedepends=(
)
options=(!strip)
source=("${pkgname}-${pkgver}.iso::https://download.ni.com/support/softlib/multifunction_daq/nidaqmxbase/${pkgver%.*}/linux/nidaqmxbase-${pkgver}.iso")
sha256sums=('594b1c07093be56fdfec783b224bd5db2c5509b95e0d30475dd5342b6efb97fa')
prepare(){
rm -f *.i386.rpm
rm *.iso
}
package(){
install -d "${pkgdir}/opt/${pkgname}"
install -m644 -Dt "${pkgdir}/usr/share/licenses/${pkgname}" -m644 LICENSE.txt
for rpmf in *.rpm; do
mv ${rpmf} ${rpmf}-ext
mkdir "${pkgdir}/opt/${pkgname}/${rpmf}"
pushd "${pkgdir}/opt/${pkgname}/${rpmf}"
bsdtar -xvf "${srcdir}/${rpmf}-ext"
popd
rm -f ${rpmf}-ext
done
cp -a * "${pkgdir}/opt/${pkgname}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |