openresty-ldap
The package builds from the official openresty.org source and a GitHub-hosted LDAP module; GitHub is not whitelisted but is a standard, trustworthy forge for open-source projects, and the module is used during build without remote code execution risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds from the official openresty.org source and a GitHub-hosted LDAP module; GitHub is not whitelisted but is a standard, trustworthy forge for open-source projects, and the module is used during build without remote code execution risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:28
source=(https://openresty.org/download/$_pkgname-$pkgver.tar.gz{,.asc}
PKGBUILD
1 offending line(s) highlighted# Maintainer: Danil Syromolotov <pelmennoteam@gmail.com>
# Base package
# URL: https://aur.archlinux.org/packages/openresty
# Maintainer: Daichi Shinozaki <dseg@shield.jp>
# Contributor: Jean-Sébastien Ney <jeansebastien.ney@gmail.com>
# Contributor: James Cleveland <jc@blackflags.co.uk>
# Contributor: Eimantas Bunevičius <eimantaster@gmail.com>
_cfgdir=/opt/openresty/nginx/conf
_tmpdir=/var/lib/openresty
_pkgname=openresty
pkgname=openresty-ldap
pkgver=1.11.2.5
pkgrel=1
pkgdesc="A Fast and Scalable Web Platform by Extending NGINX with Lua (with LDAP auth support)"
arch=('x86_64')
url="http://openresty.org/"
license=('BSD')
depends=('perl>=5.6.1' 'readline' 'pcre' 'openssl-1.0')
conflicts=('openresty')
replaces=('openresty')
install=$_pkgname.install
options=(!purge)
validpgpkeys=(
'25451EB088460026195BD62CB550E09EA0E98066'
)
source=(https://openresty.org/download/$_pkgname-$pkgver.tar.gz{,.asc}
service
$_pkgname.logrotate
$_pkgname.install
$_pkgname.sh
nginx-auth-ldap::git+https://github.com/kvspb/nginx-auth-ldap.git
)
noextract=()
sha256sums=('f8cc203e8c0fcd69676f65506a3417097fc445f57820aa8e92d7888d8ad657b9'
'SKIP'
'ec55ac7da98f5f5ec54d096c5f79b656edec0ebca835b6b9f1d20fb7be7119c5'
'613b0ed3fe4b5ee505ddb5122ee41604f464a5049be81c97601ee93970763a23'
'f071e0fd8d0d588f03fcc7db6f3cb3f7ea1b870d3416a0bde142d9aeb839d0f6'
'bf628aa47fb85f036f250416f13900be61dccac89736434498a80989b16ae85a'
'SKIP')
backup=(${_cfgdir:1}/fastcgi.conf
${_cfgdir:1}/fastcgi_params
${_cfgdir:1}/koi-win
${_cfgdir:1}/koi-utf
${_cfgdir:1}/mime.types
${_cfgdir:1}/nginx.conf
${_cfgdir:1}/scgi_params
${_cfgdir:1}/uwsgi_params
${_cfgdir:1}/win-utf
etc/logrotate.d/openresty)
build() {
cd "$srcdir/$_pkgname-$pkgver"
./configure \
--prefix=/opt/openresty \
--conf-path=$_cfgdir/nginx.conf \
--with-cc-opt="-I/usr/include/openssl-1.0/" \
--with-ld-opt="-L/usr/lib/openssl-1.0/" \
--user=http --group=http \
--with-file-aio \
--with-http_dav_module \
--with-http_gzip_static_module \
--with-http_realip_module \
--with-http_ssl_module \
--with-http_stub_status_module \
--with-mail \
--with-mail_ssl_module \
--with-ipv6 \
--with-luajit \
--with-pcre-jit \
--with-http_v2_module \
--with-stream \
--with-stream_ssl_module \
--with-http_iconv_module \
--add-module="$srcdir/nginx-auth-ldap" \
# --without-http_echo_module \ # disable ngx_http_echo_module
# --without-http_xss_module \ # disable ngx_http_xss_module
# --without-http_coolkit_module \ # disable ngx_http_coolkit_module
# --without-http_set_misc_module \ # disable ngx_http_set_misc_module
# --without-http_form_input_module \ # disable ngx_http_form_input_module
# --without-http_encrypted_session_module \
# \ # disable ngx_http_encrypted_session_module
# --without-http_srcache_module \ # disable ngx_http_srcache_module
# --without-http_lua_module \ # disable ngx_http_lua_module
# --without-http_headers_more_module \ # disable ngx_http_headers_more_module
# --without-http_array_var_module \ # disable ngx_http_array_var_module
# --without-http_memc_module \ # disable ngx_http_memc_module
# --without-http_redis2_module \ # disable ngx_http_redis2_module
# --without-http_redis_module \ # disable ngx_http_redis_module
# --without-http_auth_request_module \ # disable ngx_http_auth_request_module
# --without-http_rds_json_module \ # disable ngx_http_rds_json_module
# --without-http_rds_csv_module \ # disable ngx_http_rds_csv_module
# --without-ngx_devel_kit_module \ # disable ngx_devel_kit_module
# --without-http_ssl_module \ # disable ngx_http_ssl_module
# --with-http_iconv_module \ # enable ngx_http_iconv_module
# --with-http_drizzle_module \ # enable ngx_http_drizzle_module
# --with-http_postgres_module \ # enable ngx_http_postgres_module
# --without-lua_cjson \ # disable the lua-cjson library
# --without-lua_redis_parser \ # disable the lua-redis-parser library
# --without-lua_rds_parser \ # disable the lua-rds-parser library
# --without-lua_resty_dns \ # disable the lua-resty-dns library
# --without-lua_resty_memcached \ # disable the lua-resty-memcached library
# --without-lua_resty_redis \ # disable the lua-resty-redis library
# --without-lua_resty_mysql \ # disable the lua-resty-mysql library
# --without-lua_resty_upload \ # disable the lua-resty-upload library
# --without-lua_resty_string \ # disable the lua-resty-string library
# --without-lua51 \ # disable the bundled Lua 5.1 interpreter
# --with-lua51=PATH \ # specify the external installation of Lua 5.1 by PATH
# --with-luajit \ # enable and build LuaJIT 2.0
# --with-luajit=PATH \ # use the external LuaJIT 2.0 installation specified by PATH
# --with-luajit-xcflags=FLAGS \ # Specify extra C compiler flags for LuaJIT 2.0
# --with-libdrizzle=DIR \ # specify the libdrizzle 1.0 (or drizzle) installation prefix
# --with-libpq=DIR \ # specify the libpq (or postgresql) installation prefix
# --with-pg_config=PATH \ # specify the path of the pg_config utility
# \ # Options directly inherited from nginx
# --sbin-path=PATH \ # set nginx binary pathname
# --conf-path=PATH \ # set nginx.conf pathname
# --error-log-path=PATH \ # set error log pathname
# --pid-path=PATH \ # set nginx.pid pathname
# --lock-path=PATH \ # set nginx.lock pathname
# --tapset-prefix=PATH \ # set systemtap tapset directory prefix
# --stap-nginx-path=PATH \ # set stap-nginx pathname
# --user=USER \ # set non-privileged user for
# \ # worker processes
# --group=GROUP \ # set non-privileged group for
# \ # worker processes
# --builddir=DIR \ # set the build directory
# --with-rtsig_module \ # enable rtsig module
# --with-select_module \ # enable select module
# --without-select_module \ # disable select module
# --with-poll_module \ # enable poll module
# --without-poll_module \ # disable poll module
# --with-file-aio \ # enable file aio support
# --with-ipv6 \ # enable ipv6 support
# --with-http_realip_module \ # enable ngx_http_realip_module
# --with-http_addition_module \ # enable ngx_http_addition_module
# --with-http_xslt_module \ # enable ngx_http_xslt_module
# --with-http_image_filter_module \ # enable ngx_http_image_filter_module
# --with-http_geoip_module \ # enable ngx_http_geoip_module
# --with-http_sub_module \ # enable ngx_http_sub_module
# --with-http_dav_module \ # enable ngx_http_dav_module
# --with-http_flv_module \ # enable ngx_http_flv_module
# --with-http_gzip_static_module \ # enable ngx_http_gzip_static_module
# --with-http_random_index_module \ # enable ngx_http_random_index_module
# --with-http_secure_link_module \ # enable ngx_http_secure_link_module
# --with-http_degradation_module \ # enable ngx_http_degradation_module
# --with-http_stub_status_module \ # enable ngx_http_stub_status_module
# --without-http_charset_module \ # disable ngx_http_charset_module
# --without-http_gzip_module \ # disable ngx_http_gzip_module
# --without-http_ssi_module \ # disable ngx_http_ssi_module
# --without-http_userid_module \ # disable ngx_http_userid_module
# --without-http_access_module \ # disable ngx_http_access_module
# --without-http_auth_basic_module \ # disable ngx_http_auth_basic_module
# --without-http_autoindex_module \ # disable ngx_http_autoindex_module
# --without-http_geo_module \ # disable ngx_http_geo_module
# --without-http_map_module \ # disable ngx_http_map_module
# --without-http_split_clients_module \
# \ # disable ngx_http_split_clients_module
# --without-http_referer_module \ # disable ngx_http_referer_module
# --without-http_rewrite_module \ # disable ngx_http_rewrite_module
# --without-http_proxy_module \ # disable ngx_http_proxy_module
# --without-http_fastcgi_module \ # disable ngx_http_fastcgi_module
# --without-http_uwsgi_module \ # disable ngx_http_uwsgi_module
# --without-http_scgi_module \ # disable ngx_http_scgi_module
# --without-http_memcached_module \ # disable ngx_http_memcached_module
# --without-http_limit_zone_module \ # disable ngx_http_limit_zone_module
# --without-http_limit_req_module \ # disable ngx_http_limit_req_module
# --without-http_empty_gif_module \ # disable ngx_http_empty_gif_module
# --without-http_browser_module \ # disable ngx_http_browser_module
# --without-http_upstream_ip_hash_module \
# \ # disable ngx_http_upstream_ip_hash_module
# --with-http_perl_module \ # enable ngx_http_perl_module
# --with-perl_modules_path=PATH \ # set path to the perl modules
# --with-perl=PATH \ # set path to the perl binary
# --http-log-path=PATH \ # set path to the http access log
# --http-client-body-temp-path=PATH \ # set path to the http client request body
# \ # temporary files
# --http-proxy-temp-path=PATH \ # set path to the http proxy temporary files
# --http-fastcgi-temp-path=PATH \ # set path to the http fastcgi temporary
# \ # files
# --http-uwsgi-temp-path=PATH \ # set path to the http uwsgi temporary files
# --http-scgi-temp-path=PATH \ # set path to the http scgi temporary files
# --without-http \ # disable HTTP server
# --without-http-cache \ # disable HTTP cache
# --with-mail \ # enable POP3/IMAP4/SMTP proxy module
# --with-mail_ssl_module \ # enable ngx_mail_ssl_module
# --without-mail_pop3_module \ # disable ngx_mail_pop3_module
# --without-mail_imap_module \ # disable ngx_mail_imap_module
# --without-mail_smtp_module \ # disable ngx_mail_smtp_module
# --with-google_perftools_module \ # enable ngx_google_perftools_module
# --with-cpp_test_module \ # enable ngx_cpp_test_module
# --add-module=PATH \ # enable an external module
# --with-cc=PATH \ # set path to C compiler
# --with-cpp=PATH \ # set path to C preprocessor
# --with-cc-opt=OPTIONS \ # set additional options for C compiler
# --with-ld-opt=OPTIONS \ # set additional options for linker
# --with-cpu-opt=CPU \ # build for specified CPU, the valid values:
# \ # pentium, pentiumpro, pentium3, pentium4,
# \ # athlon, opteron, sparc32, sparc64, ppc64
# --with-make=PATH \ # specify the default make utility to be used
# --without-pcre \ # disable PCRE library usage
# --with-pcre \ # force PCRE library usage
# --with-pcre=DIR \ # set path to PCRE library sources
# --with-pcre-opt=OPTIONS \ # set additional options for PCRE building
# --with-pcre-jit \ # build PCRE with JIT compilation support
# --with-md5=DIR \ # set path to md5 library sources
# --with-md5-opt=OPTIONS \ # set additional options for md5 building
# --with-md5-asm \ # use md5 assembler sources
# --with-sha1=DIR \ # set path to sha1 library sources
# --with-sha1-opt=OPTIONS \ # set additional options for sha1 building
# --with-sha1-asm \ # use sha1 assembler sources
# --with-zlib=DIR \ # set path to zlib library sources
# --with-zlib-opt=OPTIONS \ # set additional options for zlib building
# --with-zlib-asm=CPU \ # use zlib assembler sources optimized
# \ # for specified CPU, the valid values:
# \ # pentium, pentiumpro
# --with-libatomic \ # force libatomic_ops library usage
# --with-libatomic=DIR \ # set path to libatomic_ops library sources
# --with-openssl=DIR \ # set path to OpenSSL library sources
# --with-openssl-opt=OPTIONS \ # set additional options for OpenSSL building
# --dry-run \ # dry running the configure, for testing only
# --platform=PLATFORM \ # forcibly specify a platform name, for testing only
make
}
package() {
cd "$srcdir/$_pkgname-$pkgver"
make DESTDIR="$pkgdir" install
install -Dm644 COPYRIGHT $pkgdir/usr/share/licenses/$_pkgname/LICENSE
install -d "$pkgdir"/etc/logrotate.d
install -m644 "$srcdir"/openresty.logrotate "$pkgdir"/etc/logrotate.d/openresty
install -d "$pkgdir"/$_tmpdir
install -Dm644 "$srcdir/service" "$pkgdir/usr/lib/systemd/system/openresty.service"
rm -rf "$pkgdir/var/run"
install -Dm755 $srcdir/$_pkgname.sh $pkgdir/etc/profile.d/$_pkgname.sh
}
# vim:set ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |