ozone

LOW
maintainer AlexisPolti 23 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads a source tarball from the official Segger downloads domain, which is the project's legitimate release host, and installs it as a prebuilt binary; despite the non-whitelisted host, this is a standard and expected source for the software, with no evidence of malicious behavior or supply-chain risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source tarball from the official Segger downloads domain, which is the project's legitimate release host, and installs it as a prebuilt binary; despite the non-whitelisted host, this is a standard and expected source for the software, with no evidence of malicious behavior or supply-chain risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source_x86_64=("Ozone_Linux_V${pkgver/./}_x86_64.tgz::https://www.segger.com/downloads/jlink/Ozone_Linux_V${pkgver/./}_x86_64.tgz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Alexis Polti <ArchSegger at gmail dot com>
2# Maintainer: pzl <alsoelp at gmail dot com>
3
4pkgname=ozone
5pkgver=3.50a
6pkgrel=2
7epoch=32
8pkgdesc="Segger Ozone JLink debugger for Linux"
9arch=('x86_64')
10license=('custom')
11groups=('jlink')
12replaces=('jlink-debugger')
13conflicts=('jlink-debugger')
14provides=('jlink-debugger')
15depends=('jlink-software-and-documentation>=5.10n')
16source_x86_64=("Ozone_Linux_V${pkgver/./}_x86_64.tgz::https://www.segger.com/downloads/jlink/Ozone_Linux_V${pkgver/./}_x86_64.tgz")
17source=("Ozone.desktop" "Ozone.svg")
18md5sums_x86_64=('25194f1555a757a091ff6187e024d2f3')
19md5sums=('d1d2aa1b868487207ad256ebc8235982' 'f7c46fe903305c37f38f846b18318b38')
20
21url="https://www.segger.com/jlink-software.html"
22options=(!strip)
23
24package(){
25 mv Ozone_Linux_V${pkgver/./}_x86_64 Ozone
26
27 # Match package placement from their .deb, in /opt
28 install -dm755 "${pkgdir}/opt/SEGGER/Ozone" \
29 "${pkgdir}/usr/share/licenses/${pkgname}" \
30 "${pkgdir}/usr/lib/" \
31 "${pkgdir}/usr/bin/" \
32 "${pkgdir}/usr/share/doc/${pkgname}/" \
33 "${pkgdir}/usr/share/pixmaps" \
34 "${pkgdir}/usr/share/applications"
35
36 # Install desktop entry
37 install -Dm644 "Ozone.desktop" "${pkgdir}/usr/share/applications/Ozone.desktop"
38 install -Dm644 "Ozone.svg" "${pkgdir}/usr/share/pixmaps/Ozone.svg"
39
40 cd ${srcdir}/Ozone
41
42 # Make permissions right
43 find . -type d | xargs -i'{}' chmod a+rx '{}'
44 find . -type f | xargs -i'{}' chmod a+r '{}'
45
46 # Remove un-needed files
47 find . -name ".svn" | xargs rm -rf
48
49 # Bulk copy everything
50 cp -ax Ozone ozone ozone-sim Plugins Doc Config Lib Ozone.png Examples "${pkgdir}/opt/SEGGER/Ozone"
51
52 # Create links where needed
53 ln -s /opt/SEGGER/Ozone/Doc/License.txt "${pkgdir}/usr/share/licenses/${pkgname}/"
54 ln -s /opt/SEGGER/Ozone/Ozone "${pkgdir}/usr/bin"
55 ln -s /opt/SEGGER/Ozone/ozone-sim "${pkgdir}/usr/bin"
56
57 for f in Doc/*; do
58 ln -s /opt/SEGGER/Ozone/"$f" "${pkgdir}/usr/share/doc/${pkgname}"
59 done
60}
61

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion