ni-daqmx-base-bin

maintainer greyltc · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The package downloads a prebuilt ISO from download.ni.com, which is National Instruments' (now NI/Emerson) official software distribution domain — this is the legitimate vendor host for NI-DAQmx Base. The ISO contains RPMs that are extracted and installed under /opt. While the host is the official NI download server (not a personal or unofficial host), the package installs prebuilt binary RPMs without source code, and the extraction logic is somewhat sloppy (cp -a * copies everything including leftover artifacts). The sha256sum is present and pinned. The main concern is that binary-only driver software from a closed-source vendor is being extracted and placed under /opt without any integrity verification of individual RPMs beyond the ISO checksum. This is a legitimate medium-risk supply-chain concern: executed binary code from a closed-source vendor with no source verification, though the host itself is the official NI distribution server. Not high because there is no evidence of malice, obfuscation, or unofficial hosting.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("${pkgname}-${pkgver}.iso::https://download.ni.com/support/softlib/multifunction_daq/nidaqmxbase/${pkgver%.*}/linux/nidaqmxbase-${pkgver}.iso")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The package downloads a prebuilt ISO from download.ni.com, which is National Instruments' (now NI/Emerson) official software distribution domain — this is the legitimate vendor host for NI-DAQmx Base. The ISO contains RPMs that are extracted and installed under /opt. While the host is the official NI download server (not a personal or unofficial host), the package installs prebuilt binary RPMs without source code, and the extraction logic is somewhat sloppy (cp -a * copies everything including leftover artifacts). The sha256sum is present and pinned. The main concern is that binary-only driver software from a closed-source vendor is being extracted and placed under /opt without any integrity verification of individual RPMs beyond the ISO checksum. This is a legitimate medium-risk supply-chain concern: executed binary code from a closed-source vendor with no source verification, though the host itself is the official NI distribution server. Not high because there is no evidence of malice, obfuscation, or unofficial hosting.

PKGBUILD

1 offending line(s) highlighted
1pkgname=ni-daqmx-base-bin
2pkgver=15.0.0
3pkgrel=1
4pkgdesc="a subset of NI-DAQmx functionality for your data acquisition system"
5arch=(x86_64)
6url="https://www.ni.com/en-gb/support/downloads/drivers/download.ni-daqmx-base.html#326057"
7license=(custom)
8depends=(
9)
10makedepends=(
11)
12options=(!strip)
13source=("${pkgname}-${pkgver}.iso::https://download.ni.com/support/softlib/multifunction_daq/nidaqmxbase/${pkgver%.*}/linux/nidaqmxbase-${pkgver}.iso")
14sha256sums=('594b1c07093be56fdfec783b224bd5db2c5509b95e0d30475dd5342b6efb97fa')
15
16prepare(){
17 rm -f *.i386.rpm
18 rm *.iso
19}
20
21package(){
22 install -d "${pkgdir}/opt/${pkgname}"
23 install -m644 -Dt "${pkgdir}/usr/share/licenses/${pkgname}" -m644 LICENSE.txt
24 for rpmf in *.rpm; do
25 mv ${rpmf} ${rpmf}-ext
26 mkdir "${pkgdir}/opt/${pkgname}/${rpmf}"
27 pushd "${pkgdir}/opt/${pkgname}/${rpmf}"
28 bsdtar -xvf "${srcdir}/${rpmf}-ext"
29 popd
30 rm -f ${rpmf}-ext
31 done
32
33 cp -a * "${pkgdir}/opt/${pkgname}"
34}
35

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion