ntfy-alertmanager
The source is a versioned tarball from the maintainer's own git server, which hosts the project; building from this source is normal for AUR packages and poses low risk despite the non-whitelisted host.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a versioned tarball from the maintainer's own git server, which hosts the project; building from this source is normal for AUR packages and poses low risk despite the non-whitelisted host.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
"https://git.xenrox.net/~xenrox/ntfy-alertmanager/refs/download/v$pkgver/$pkgname-$pkgver.tar.gz"{,.sig}
PKGBUILD
1 offending line(s) highlighted# Maintainer: Thorben Günther <admin@xenrox.net>
pkgname=ntfy-alertmanager
pkgver=1.0.1
pkgrel=1
pkgdesc='A bridge between ntfy and Alertmanager'
arch=('x86_64')
url='https://hub.xenrox.net/~xenrox/ntfy-alertmanager'
license=('AGPL3')
makedepends=('go')
optdepends=(
'redis: Persistent cache with Redis'
)
options=('!lto')
backup=('etc/ntfy-alertmanager/config')
source=(
"https://git.xenrox.net/~xenrox/ntfy-alertmanager/refs/download/v$pkgver/$pkgname-$pkgver.tar.gz"{,.sig}
"ntfy-alertmanager.service"
"sysusers.conf"
)
sha256sums=('2f95b227e3b8e4e280c1d84c19bfa3fd4412cf5f67c1d531edb133c91b0df23d'
'SKIP'
'3c87f8d84854f04d362892b2a74660d0d48ca65030c0ab659827e9b32e532172'
'7d9183eac94bedc9c82b4abcb6b50b262599f079d2d078cdafe5bb6019464da4')
validpgpkeys=('BBC78A8FF5467A292893AE702698363BB3DBBAEE')
prepare() {
cd "$pkgname-$pkgver"
export GOPATH="${srcdir}"
go mod download
}
build() {
cd "$pkgname-$pkgver"
export CGO_CPPFLAGS="${CPPFLAGS}"
export CGO_CFLAGS="${CFLAGS}"
export CGO_CXXFLAGS="${CXXFLAGS}"
export CGO_LDFLAGS="${LDFLAGS}"
export GOPATH="${srcdir}"
go build \
-buildmode=pie \
-trimpath \
-mod=readonly \
-modcacherw \
-ldflags "-linkmode external -X main.version=v${pkgver} -extldflags \"${LDFLAGS}\"" \
-o ntfy-alertmanager
}
check() {
cd "$pkgname-$pkgver"
go test ./...
}
package() {
cd "$pkgname-$pkgver"
install -Dm755 ntfy-alertmanager "$pkgdir"/usr/bin/ntfy-alertmanager
install -Dm644 ../ntfy-alertmanager.service -t "$pkgdir"/usr/lib/systemd/system/
install -Dm644 ../sysusers.conf "$pkgdir"/usr/lib/sysusers.d/ntfy-alertmanager.conf
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |