pascom-client
maintainer she11sh0cked
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a source tarball from the official vendor's domain (my.pascom.net) which is plausibly the project's own release infrastructure; despite the non-whitelisted host, this is a standard AUR practice for building from official upstream sources, and the checksums are provided and verifiable.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source tarball from the official vendor's domain (my.pascom.net) which is plausibly the project's own release infrastructure; despite the non-whitelisted host, this is a standard AUR practice for building from official upstream sources, and the checksums are provided and verifiable.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
"pascom_Client-${pkgver}-linux.tar.bz2::https://my.pascom.net/update/client/cloud/linux"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: she11sh0cked <22623152+she11sh0cked@users.noreply.github.com>
2
3
pkgname=pascom-client
4
pkgver=106.R3601
5
pkgrel=2
6
pkgdesc="Pascom Client"
7
arch=('x86_64')
8
url="https://www.pascom.net/"
9
license=('custom: commercial')
10
optdepends=('xcb-util-cursor: Needed for mouse cursor support under X11')
11
source=(
12
"pascom_Client-${pkgver}-linux.tar.bz2::https://my.pascom.net/update/client/cloud/linux"
13
"${pkgname}.desktop"
14
)
15
16
sha256sums=(
17
"c7acfa3851a2877326900f5101217880f183ac8b088151d09c583e8942794579"
18
"c59ab91a5cb239d50bc35f21bc884c1dfb3a4e1b6ce3c2478bc229f56c83dc15"
19
)
20
21
pkgver() {
22
IFS='/' read -ra ADDR <<<$(curl -ILs -o /dev/null -w %{url_effective} https://my.pascom.net/update/client/cloud/linux)
23
echo ${ADDR[6]} | sed 's/pascom_Client.//g' | sed 's/.linux.tar.bz2//g'
24
}
25
26
package() {
27
_pkg=pascom_Client
28
29
install -d "${pkgdir}/opt/${pkgname}"
30
install -d "${pkgdir}/usr/share/applications"
31
install -d "${pkgdir}/usr/share/icons"
32
33
install -m644 "${srcdir}/${_pkg}/client.png" "${pkgdir}/usr/share/icons/${pkgname}.png"
34
install -m644 "${srcdir}/${pkgname}.desktop" "${pkgdir}/usr/share/applications/${pkgname}.desktop"
35
36
cp -r "${srcdir}/${_pkg}/"* "${pkgdir}/opt/${pkgname}" -R
37
}
38
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |