nordlayer
maintainer raverecursion
· 5 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a prebuilt .deb from the official vendor's domain (downloads.nordlayer.com), which is plausibly part of their official release infrastructure; while the host is not a standard forge, it is vendor-controlled, and the checksum is provided, reducing supply-chain risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt .deb from the official vendor's domain (downloads.nordlayer.com), which is plausibly part of their official release infrastructure; while the host is not a standard forge, it is vendor-controlled, and the checksum is provided, reducing supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
source_x86_64=("https://downloads.nordlayer.com/linux/latest/debian/pool/main/nordlayer_${pkgver}_amd64.deb")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Roland Kiraly <rolandgyulakiraly at outlook dot com>
2
# https://github.com/raverecursion/nordlayer-latest/tree/master
3
pkgname=nordlayer
4
pkgver=3.5.0
5
pkgrel=1
6
pkgdesc="Proprietary VPN client for Linux"
7
arch=('x86_64')
8
url="https://nordlayer.com"
9
license=('custom:commercial')
10
replaces=('nordvpnteams-bin')
11
conflicts=('nordvpnteams-bin' 'nordlayer-bin')
12
depends=('bash' 'libgcrypt' 'libgpg-error' 'libcap' 'hicolor-icon-theme' 'gmp' 'strongswan')
13
options=('!strip' '!emptydirs')
14
install=${pkgname}.install
15
source_x86_64=("https://downloads.nordlayer.com/linux/latest/debian/pool/main/nordlayer_${pkgver}_amd64.deb")
16
sha512sums_x86_64=('3096474b7079287f6fcda6bd4327709db7651eca211ae791150612cf6c018a6ba963443cee4d33f61b7ca0cec46fda6b13a89a0507422da1ed3003342b653b1e')
17
18
package() {
19
cd "${srcdir}"
20
# Extract the control and data tarballs from the .deb file
21
ar x "${srcdir}/nordlayer_${pkgver}_amd64.deb"
22
23
# Extract the data.tar.gz into the pkgdir
24
tar -xzf data.tar.gz -C "${pkgdir}"
25
26
# Move sbin binaries to bin
27
if [ -d "${pkgdir}/usr/sbin" ]; then
28
mv "${pkgdir}/usr/sbin"/* "${pkgdir}/usr/bin"
29
# Update the systemd service file to point to /usr/bin instead of /usr/sbin
30
sed -i 's+/usr/sbin+/usr/bin+g' "${pkgdir}/usr/lib/systemd/system/nordlayer.service"
31
# Remove the now-empty sbin directory
32
rm -r "${pkgdir}/usr/sbin"
33
fi
34
}
35
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |