ozone
The package downloads a source tarball from the official Segger downloads domain, which is the project's legitimate release host, and installs it as a prebuilt binary; despite the non-whitelisted host, this is a standard and expected source for the software, with no evidence of malicious behavior or supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source tarball from the official Segger downloads domain, which is the project's legitimate release host, and installs it as a prebuilt binary; despite the non-whitelisted host, this is a standard and expected source for the software, with no evidence of malicious behavior or supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
source_x86_64=("Ozone_Linux_V${pkgver/./}_x86_64.tgz::https://www.segger.com/downloads/jlink/Ozone_Linux_V${pkgver/./}_x86_64.tgz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Alexis Polti <ArchSegger at gmail dot com>
# Maintainer: pzl <alsoelp at gmail dot com>
pkgname=ozone
pkgver=3.50a
pkgrel=2
epoch=32
pkgdesc="Segger Ozone JLink debugger for Linux"
arch=('x86_64')
license=('custom')
groups=('jlink')
replaces=('jlink-debugger')
conflicts=('jlink-debugger')
provides=('jlink-debugger')
depends=('jlink-software-and-documentation>=5.10n')
source_x86_64=("Ozone_Linux_V${pkgver/./}_x86_64.tgz::https://www.segger.com/downloads/jlink/Ozone_Linux_V${pkgver/./}_x86_64.tgz")
source=("Ozone.desktop" "Ozone.svg")
md5sums_x86_64=('25194f1555a757a091ff6187e024d2f3')
md5sums=('d1d2aa1b868487207ad256ebc8235982' 'f7c46fe903305c37f38f846b18318b38')
url="https://www.segger.com/jlink-software.html"
options=(!strip)
package(){
mv Ozone_Linux_V${pkgver/./}_x86_64 Ozone
# Match package placement from their .deb, in /opt
install -dm755 "${pkgdir}/opt/SEGGER/Ozone" \
"${pkgdir}/usr/share/licenses/${pkgname}" \
"${pkgdir}/usr/lib/" \
"${pkgdir}/usr/bin/" \
"${pkgdir}/usr/share/doc/${pkgname}/" \
"${pkgdir}/usr/share/pixmaps" \
"${pkgdir}/usr/share/applications"
# Install desktop entry
install -Dm644 "Ozone.desktop" "${pkgdir}/usr/share/applications/Ozone.desktop"
install -Dm644 "Ozone.svg" "${pkgdir}/usr/share/pixmaps/Ozone.svg"
cd ${srcdir}/Ozone
# Make permissions right
find . -type d | xargs -i'{}' chmod a+rx '{}'
find . -type f | xargs -i'{}' chmod a+r '{}'
# Remove un-needed files
find . -name ".svn" | xargs rm -rf
# Bulk copy everything
cp -ax Ozone ozone ozone-sim Plugins Doc Config Lib Ozone.png Examples "${pkgdir}/opt/SEGGER/Ozone"
# Create links where needed
ln -s /opt/SEGGER/Ozone/Doc/License.txt "${pkgdir}/usr/share/licenses/${pkgname}/"
ln -s /opt/SEGGER/Ozone/Ozone "${pkgdir}/usr/bin"
ln -s /opt/SEGGER/Ozone/ozone-sim "${pkgdir}/usr/bin"
for f in Doc/*; do
ln -s /opt/SEGGER/Ozone/"$f" "${pkgdir}/usr/share/doc/${pkgname}"
done
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |