oopsmate-git
The package downloads prebuilt NNUE network data files from a non-whitelisted but official and plausibly secure stockfishchess.org subdomain; these are static data files, not executables, used by the engine and not executed directly, so the worst-case impact of a compromised source is limited to data tampering, not code execution.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt NNUE network data files from a non-whitelisted but official and plausibly secure stockfishchess.org subdomain; these are static data files, not executables, used by the engine and not executed directly, so the worst-case impact of a compromised source is limited to data tampering, not code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
"nn-1c0000000000.nnue::https://data.stockfishchess.org/nn/nn-1c0000000000.nnue"
PKGBUILD
1 offending line(s) highlighted# Maintainer: PS-Wizard (packaged for AUR)
pkgname=oopsmate-git
pkgver=r0.0000000
pkgrel=1
pkgdesc='UCI chess engine in Rust (git)'
arch=('x86_64')
url='https://github.com/PS-Wizard/oopsmate'
license=('GPL-3.0-only')
makedepends=('git' 'rust')
provides=('oopsmate')
conflicts=('oopsmate')
source=(
"git+${url}.git"
"nn-1c0000000000.nnue::https://data.stockfishchess.org/nn/nn-1c0000000000.nnue"
"nn-37f18f62d772.nnue::https://data.stockfishchess.org/nn/nn-37f18f62d772.nnue"
)
sha256sums=(
'SKIP'
'SKIP'
'SKIP'
)
prepare() {
cd "$srcdir/oopsmate"
# The engine embeds SF17 NNUE networks via include_bytes!, but the upstream git repo
# does not track the binary `.nnue` blobs. Ship them as AUR sources and place them
# into the expected in-tree path before compiling.
install -Dm644 "$srcdir/nn-1c0000000000.nnue" \
"$srcdir/oopsmate/crates/nnuebie/archive/nnue/networks/nn-1c0000000000.nnue"
install -Dm644 "$srcdir/nn-37f18f62d772.nnue" \
"$srcdir/oopsmate/crates/nnuebie/archive/nnue/networks/nn-37f18f62d772.nnue"
}
pkgver() {
cd "$srcdir/oopsmate"
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
}
build() {
cd "$srcdir/oopsmate"
# Match the engine's local build flags and satisfy strikes' BMI2 requirement.
# AUR builds from source on the user's machine; `native` is intentional.
export RUSTFLAGS="${RUSTFLAGS} -C target-cpu=native -C target-feature=+avx2,+bmi2,-avx512f,-avx512vl,-avx512bw"
cargo build --release --locked --bins
}
check() {
cd "$srcdir/oopsmate"
export RUSTFLAGS="${RUSTFLAGS} -C target-cpu=native -C target-feature=+avx2,+bmi2,-avx512f,-avx512vl,-avx512bw"
cargo test --release --locked
}
package() {
cd "$srcdir/oopsmate"
install -Dm755 target/release/oops_mate "$pkgdir/usr/bin/oops_mate"
install -Dm755 target/release/oopsmate-nnue "$pkgdir/usr/bin/oopsmate-nnue"
install -Dm755 target/release/oopsmate-pesto "$pkgdir/usr/bin/oopsmate-pesto"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |