opentracker
The source URL is on the project's official domain (erdgeist.org), which is the maintainer's own site; downloading the tarball and a CVS dependency from the same trusted upstream is standard practice and not inherently risky.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source URL is on the project's official domain (erdgeist.org), which is the maintainer's own site; downloading the tarball and a CVS dependency from the same trusted upstream is standard practice and not inherently risky.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:20
"https://erdgeist.org/arts/software/${pkgname}/${pkgname}-${pkgver}.tar.bz2"
PKGBUILD
1 offending line(s) highlighted# Maintainer: txtsd <aur.archlinux@ihavea.quest>
# Contributor: Dan Johansen <strit83 at gmail dot com>
# Contributor: Oleg Rakhmanov <oleg [at] archlinuxarm [dot] org>
pkgname=opentracker
pkgver=1.0
pkgrel=3
epoch=1
pkgdesc='A free and open torrent tracker'
arch=(x86_64 i686 armv7h aarch64)
url='http://erdgeist.org/arts/software/opentracker/'
license=('LicenseRef-Beerware')
depends=(glibc zlib)
makedepends=(
cvs
gcc
)
backup=('etc/opentracker/opentracker.conf')
source=(
"https://erdgeist.org/arts/software/${pkgname}/${pkgname}-${pkgver}.tar.bz2"
'opentracker.service'
'opentracker.sysusers'
'opentracker.tmpfiles'
)
sha256sums=('8109cbf271d4374020af719aca5448b1354517c0b2f4b74b167332944a61eb31'
'6bd91237855a0ed06eeaf4182d565a9125dbf89f2dfb3e83b5607f7c9a89d00d'
'c0097bc231e0f6f7c8ff17e3cca99f2215218cc227476a4390936b04300c8fc7'
'0c7f180db96168dd7546b30cb276ab1058201c919059b251d84868fe63990f08')
_cvsroot=':pserver:cvs@cvs.fefe.de:/cvs'
_cvsmod='libowfat'
prepare() {
cd "${srcdir}"
echo "Getting ${_cvsmod} from ${_cvsroot} ..."
if [ -d "${_cvsmod}/CVS" ]; then
cd "${_cvsmod}"
cvs -z9 update -d
else
cvs -d "${_cvsroot}" -z9 co "${_cvsmod}"
fi
}
build() {
cd libowfat
make
cd ..
cd "opentracker-${pkgver}"
make
}
package() {
install -Dm755 "${pkgname}-${pkgver}/${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
install -Dm755 "${pkgname}-${pkgver}/${pkgname}.conf.sample" "${pkgdir}/etc/${pkgname}/${pkgname}.conf"
install -Dm644 "${pkgname}.service" "${pkgdir}/usr/lib/systemd/system/${pkgname}.service"
install -Dm644 "${pkgname}.sysusers" "${pkgdir}/usr/lib/sysusers.d/${pkgname}.conf"
install -Dm644 "${pkgname}.tmpfiles" "${pkgdir}/usr/lib/tmpfiles.d/${pkgname}.conf"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |