oracle-instantclient-odbc
maintainer Malvineous
· 7 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a prebuilt Oracle ODBC library from Oracle's official download domain (oracle.com), which is a legitimate vendor host; despite the static analyzer flag for a non-standard host, this is a normal and expected source for Oracle Instant Client packages, and the checksums are provided and verifiable.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt Oracle ODBC library from Oracle's official download domain (oracle.com), which is a legitimate vendor host; despite the static analyzer flag for a non-standard host, this is a normal and expected source for Oracle Instant Client packages, and the checksums are provided and verifiable.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:22
source=("https://download.oracle.com/otn_software/linux/instantclient/${_urlver}/${_pkgname}-linux.x64-${pkgver}${_pkgver_vendor_suffix}.zip")
PKGBUILD
1 offending line(s) highlighted
1
# Contributor: Adam Nielsen <malvineous@shikadi.net>
2
# Contributor: Vitaliy Berdinskikh <skipper13@archlinux.org.ua>
3
# Contributor: Andrea Agosti <cifvts@gmail.com>
4
# Contributor: Viliam Pucik <viliam.pucik@gmail.com>
5
# Maintainer: Adam Nielsen <malvineous@shikadi.net>
6
7
_pkgname=instantclient-odbc
8
pkgname=oracle-${_pkgname}
9
pkgver=23.26.2.0.0
10
_pkgver_vendor_suffix=
11
_urlver=2326200v2
12
_unzippath=instantclient_23_26
13
pkgrel=1
14
pkgdesc="Additional libraries for enabling ODBC applications with Instant Client"
15
arch=('x86_64')
16
url="https://www.oracle.com/at/database/technologies/instant-client/downloads.html"
17
license=('custom:OTN')
18
depends=(oracle-instantclient-basic=$pkgver)
19
replaces=('instantclient-odbc')
20
options=(!strip)
21
22
source=("https://download.oracle.com/otn_software/linux/instantclient/${_urlver}/${_pkgname}-linux.x64-${pkgver}${_pkgver_vendor_suffix}.zip")
23
md5sums=('e86aa99545eba5300db5bc604e601dc7')
24
sha256sums=('c3bfe1379457ca83ae907823c3165077957e9bb50938192962ff91972135b44d')
25
26
package() {
27
local basedir="$srcdir/${_unzippath}"
28
29
install -d "$pkgdir/usr/lib"
30
# Copy files but not symlinks
31
install -m 755 -t "$pkgdir/usr/lib" `find "$basedir" -type f -name '*.so*'`
32
33
install -d "$pkgdir/usr/share/oracle"
34
install -m 755 -t "$pkgdir/usr/share/oracle" "$basedir/"*.sh
35
36
install -d "$pkgdir/usr/share/doc/oracle"
37
install -m 644 -t "$pkgdir/usr/share/doc/oracle" "$basedir/"*README*
38
39
install -Dm644 -t "$pkgdir/usr/share/licenses/$pkgname" "$basedir/"*LICENSE
40
41
# create required symlinks
42
cd "$pkgdir/usr/lib" || return 1
43
local lib link
44
for lib in *.so*; do
45
link=$lib
46
while [[ ${link#*.} != so ]]; do
47
link=${link%.*}
48
ln -s $lib $link
49
done
50
done
51
52
}
53
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |