oracle-instantclient-sdk
maintainer Malvineous
· 18 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a legitimate Oracle SDK header file from Oracle's official download domain, used for development; installing header files poses no execution risk, and the host, while not whitelisted, is plausibly Oracle's official infrastructure.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a legitimate Oracle SDK header file from Oracle's official download domain, used for development; installing header files poses no execution risk, and the host, while not whitelisted, is plausibly Oracle's official infrastructure.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:31
source=("https://download.oracle.com/otn_software/linux/instantclient/${_urlver}/${_pkgname}-linux.x64-${pkgver}${_pkgver_vendor_suffix}.zip")
PKGBUILD
1 offending line(s) highlighted
1
# Contributor: Adam Nielsen <malvineous@shikadi.net>
2
# Contributor: Vitaliy Berdinskikh <skipper13@archlinux.org.ua>
3
# Contributor: Andrea Agosti <cifvts@gmail.com>
4
# Contributor: Viliam Pucik <viliam.pucik@gmail.com>
5
# Maintainer: Adam Nielsen <malvineous@shikadi.net>
6
7
# This package is also available as a Pacman repo, to simplify upgrades.
8
# Add the following lines to the end of /etc/pacman.conf:
9
#
10
# [oracle]
11
# SigLevel = Optional TrustAll
12
# Server = http://linux.shikadi.net/arch/$repo/$arch/
13
#
14
# Then run `pacman -Sy` then `pacman -S oracle-instantclient-sdk`
15
16
_pkgname=instantclient-sdk
17
pkgname=oracle-${_pkgname}
18
pkgver=23.26.2.0.0
19
_pkgver_vendor_suffix=
20
_urlver=2326200v2
21
_unzippath=instantclient_23_26
22
pkgrel=1
23
pkgdesc="Additional header files for developing Oracle applications with Instant Client"
24
arch=('x86_64')
25
url="https://www.oracle.com/at/database/technologies/instant-client/downloads.html"
26
license=('custom:OTN')
27
depends=(oracle-instantclient-basic=$pkgver)
28
replaces=('instantclient-sdk')
29
options=(!strip)
30
31
source=("https://download.oracle.com/otn_software/linux/instantclient/${_urlver}/${_pkgname}-linux.x64-${pkgver}${_pkgver_vendor_suffix}.zip")
32
md5sums=('1d898351f02ac26278887bd3808fe66c')
33
sha256sums=('71c2c9ad3c5789804bb3d034d17ac82f284a807b87d312752c6e63d68974dc21')
34
35
package() {
36
# Put all .h files into /usr/include
37
cd "$srcdir/${_unzippath}/"
38
install -d "$pkgdir/usr/include"
39
install -m 644 -t "$pkgdir/usr/include" sdk/include/*.h
40
# But we don't want this one, it is unused and it conflicts with another
41
rm "$pkgdir/usr/include/ldap.h"
42
43
install -Dm644 -t "$pkgdir/usr/share/licenses/$pkgname" *LICENSE
44
}
45
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |