qfinderpro-bin
The package downloads a prebuilt .deb from QNAP's official domain (download.qnap.com), which is the vendor's legitimate release infrastructure; despite the static analyzer flag for a non-whitelisted host, the source is trustworthy and the package installs only vendor-provided binaries with no obfuscated or remote code execution.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt .deb from QNAP's official domain (download.qnap.com), which is the vendor's legitimate release infrastructure; despite the static analyzer flag for a non-whitelisted host, the source is trustworthy and the package installs only vendor-provided binaries with no obfuscated or remote code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:33
"${pkgname}-${pkgver}.deb::https://download.qnap.com/Storage/Utility/QNAPQfinderProUbuntux64-${pkgver}.deb"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Sato Ki <satoki at em dot advant dot click>
pkgname=qfinderpro-bin
pkgver=7.14.1.0727
pkgrel=1
pkgdesc="Quickly find and easily access all of the QNAP NAS on the same LAN."
url="https://www.qnap.com/en/utilities/essentials"
arch=('x86_64')
license=('custom')
makedepends=('patchelf')
depends=(
'dbus'
'desktop-file-utils'
'fontconfig'
'freetype2'
'gcc-libs'
'glib2'
'glibc'
'libglvnd'
'libjpeg-turbo'
'libpng'
'libx11'
'libxcb'
'libxkbcommon'
'libxkbcommon-x11'
'pcre2'
'xcb-util-image'
'xcb-util-keysyms'
'xcb-util-renderutil'
'xcb-util-wm'
'zlib'
)
source=(
"${pkgname}-${pkgver}.deb::https://download.qnap.com/Storage/Utility/QNAPQfinderProUbuntux64-${pkgver}.deb"
"QNAPQfinderPro.desktop.patch"
"QfinderPro.sh.patch"
"QfinderUpload.sh.patch"
)
noextract=()
sha256sums=(
'88ec61efcb643c710fa8c91dd0e1d1001244fb568b4cee5fd5a8ed0f1ea84844'
'3994451507c01136c178feabd411ea7dbb44616370a174af34931a6114dc19ee'
'd100cbe26eadfef6a7047569f276547825f72c7a14e1845d2366819205cf7abe'
'aa1ff8338052ae63e8380d80ac35f0cd702c2bab1157187a78043f73bb3f848a'
)
package() {
cd $srcdir
ar x "${pkgname}-${pkgver}.deb"
# The upstream deb ships binaries in /usr/local/bin/QNAP and the bundled Qt5
# in /usr/local/lib/QNAP; merge both into /opt/QNAP/QfinderPro.
tar --no-same-owner --transform='s#usr/local/bin/QNAP#opt/QNAP#' \
--transform='s#usr/local/lib/QNAP#opt/QNAP#' \
-xf "${srcdir}/data.tar.zst" -C "${pkgdir}/"
# The bare directory entries under usr/local survive the transform.
rm -rf "${pkgdir}/usr/local"
patch "${pkgdir}/usr/share/applications/QNAPQfinderPro.desktop" < "${srcdir}/QNAPQfinderPro.desktop.patch"
patch "${pkgdir}/opt/QNAP/QfinderPro/QfinderPro.sh" < "${srcdir}/QfinderPro.sh.patch"
patch "${pkgdir}/opt/QNAP/QfinderPro/QfinderUpload.sh" < "${srcdir}/QfinderUpload.sh.patch"
# QfinderPro's RUNPATH still points at the old /usr/local location.
patchelf --set-rpath '$ORIGIN' "${pkgdir}/opt/QNAP/QfinderPro/QfinderPro" \
"${pkgdir}/opt/QNAP/QfinderPro/QfinderUpload"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |