rclone-beta-bin

LOW
maintainer lapsus 1 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads prebuilt rclone binaries from the official beta.rclone.org domain, which is the project's own release infrastructure; despite the static analyzer flag for non-whitelisted host, this is a legitimate source for beta releases and the binaries are verified with b2sums.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt rclone binaries from the official beta.rclone.org domain, which is the project's own release infrastructure; despite the static analyzer flag for non-whitelisted host, this is a legitimate source for beta releases and the binaries are verified with b2sums.

2 higher static findings superseded - not the current verdict (shown for transparency)
Medium External download from an untrusted host, not in source=() external_download_not_in_source

curl/wget fetches a URL on a non-allowlisted host that is not part of source=(), so it is not checksum-verified by makepkg.

  • PKGBUILD:37 size=$(curl -fsSI --http1.1 "https://beta.rclone.org/rclone-beta-latest-linux-amd64.zip" |
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:23 source_i686=("rclone-v${_upver}-linux-386.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-386.zip")

PKGBUILD

2 offending line(s) highlighted
1#!/bin/bash
2
3# Maintainer: PumpkinCheshire <me at pumpkincheshire dot com>
4
5pkgname=rclone-beta-bin
6_srcname=rclone
7pkgrel=1
8pkgver=1.76.0_beta.10425.9dc8b71ae
9_upver=${pkgver//_/-}
10pkgdesc="Sync files to and from Google Drive, S3, Swift, Cloudfiles, Dropbox and Google Cloud Storage. (Beta version)"
11provides=('rclone')
12conflicts=('rclone' 'rclone-git' 'rclone-bin')
13url="https://beta.rclone.org/"
14license=('MIT')
15options=('!debug')
16depends=('glibc')
17arch=('i686' 'x86_64' 'armv6h' 'armv7h' 'aarch64')
18_arch='linux-386'
19[ "$CARCH" = 'x86_64' ] && _arch='linux-amd64'
20[ "$CARCH" = 'armv6h' ] && _arch='linux-arm'
21[ "$CARCH" = 'armv7h' ] && _arch='linux-arm-v7'
22[ "$CARCH" = 'aarch64' ] && _arch='linux-arm64'
23source_i686=("rclone-v${_upver}-linux-386.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-386.zip")
24source_x86_64=("rclone-v${_upver}-linux-amd64.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-amd64.zip")
25source_armv6h=("rclone-v${_upver}-linux-arm.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-arm.zip")
26source_armv7h=("rclone-v${_upver}-linux-arm-v7.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-arm-v7.zip")
27source_aarch64=("rclone-v${_upver}-linux-arm64.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-arm64.zip")
28
29b2sums_i686=('311ca703d1b20745992a9cac9bfe6bf0220c1fac2403a4481d4ee43bb0a6e3c2be7e711792590ce6107830597d982ec0c7f5eb73d376ba0ced6ea917bf0dfbb8')
30b2sums_x86_64=('1a3c83d40ea954dae90cd0b4bc541ffe7bc6da6ac370f08e6154e751abe6b0750ddc827a777f01d095e18dab6ce330fc3931b7e5ee1c73c3200af120def0be21')
31b2sums_armv6h=('2702b9e16b5bc7c70ff7d42050384c1f68074d03b116aa2ff2dbaa1dd76575fe28ed2c245becb0246fa6e007e996e3bdac9f86bfafdd4a8479e48eb9bc37382b')
32b2sums_armv7h=('24f8a207ae431150a279be8d49ccd55a3f8fdf930606d78bcdc1403fba268e7c205d20d298dd041742bb049aae190f68b981e28e0ed10ec5fbe340f216dec3e4')
33b2sums_aarch64=('c1f05d32c979f6ea0bd300c915f2872588f5cac3b1d07398ec4989f129c87b13546fb68d80b4ef63852469d09d75381e914b310c3c2d622876afdde363524081')
34
35latestver() {
36 local size ver
37 size=$(curl -fsSI --http1.1 "https://beta.rclone.org/rclone-beta-latest-linux-amd64.zip" |
38 sed -nE 's/^content-length: *([0-9]+).*/\1/Ip') || return 1
39 [[ -n $size ]] || return 1
40 ver=$(curl -fsS --http1.1 -r "$((size - 4096))-$((size - 1))" \
41 "https://beta.rclone.org/rclone-beta-latest-linux-amd64.zip" |
42 strings | grep -oP 'rclone-v\K[0-9]+\.[0-9]+\.[0-9]+-beta\.[0-9]+\.[0-9a-f]+' |
43 head -1) || return 1
44 [[ -n $ver ]] || return 1
45 printf '%s\n' "$ver" | tr '-' '_'
46}
47
48
49package() {
50 cd "$srcdir/${_srcname}-v${_upver}-${_arch}" || exit
51
52 install -Dm755 rclone "$pkgdir/usr/bin/rclone"
53
54 # install -Dm644 $srcdir/COPYING "$pkgdir/usr/share/licenses/$pkgname/COPYING"
55 install -Dm644 rclone.1 "$pkgdir/usr/share/man/man1/rclone.1"
56 install -d "$pkgdir/usr/share/doc/$pkgname"
57 install -t "$pkgdir/usr/share/doc/$pkgname" -m644 README.html README.txt
58}
59

Changes since previous scan

--- PKGBUILD @ 2026-09-27 00:07
+++ PKGBUILD @ 2026-10-02 00:00
@@ -5,7 +5,7 @@
pkgname=rclone-beta-bin
_srcname=rclone
pkgrel=1
-pkgver=1.76.0_beta.10418.ce5351c52
+pkgver=1.76.0_beta.10425.9dc8b71ae
_upver=${pkgver//_/-}
pkgdesc="Sync files to and from Google Drive, S3, Swift, Cloudfiles, Dropbox and Google Cloud Storage. (Beta version)"
provides=('rclone')
@@ -26,11 +26,11 @@
source_armv7h=("rclone-v${_upver}-linux-arm-v7.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-arm-v7.zip")
source_aarch64=("rclone-v${_upver}-linux-arm64.zip::https://beta.rclone.org/v${_upver}/rclone-v${_upver}-linux-arm64.zip")
-b2sums_i686=('92af9163a1490d21c0ac7a1343a6a46adb710c5721adaa7a72e107a116039569b48c72800676e7280a37615f002af532ba0ef9e89a79d0e5b545fb185743e2e1')
-b2sums_x86_64=('d4e6653a98de961df0a773c1d3c2f513120f0f8fb29a2348822dedb2d5c74e12f29af5a67093214eae44119c191115dfc13a50388e600364d7241869f06a4197')
-b2sums_armv6h=('d885f3270bb32bdd61a9ed1e4e4522578e1b8c07ad3c53a1753620d04fa77bc4aff8328989f0a503286072aaee19fb02f6035396d612d7121b1b3b8f1521616d')
-b2sums_armv7h=('4e321ba852d10b63afc947e3c21807c7f30e8994c5b40fb7c1a323b407e0ad35a3889cc7d5917c2e8517a86d7fd5794179fd0d3958a7db80920d565202c47775')
-b2sums_aarch64=('b01f77acb1bb2e2132e2998a53c7b91c969d6b03cefd555be1d57c16016bc6c7708997901a7321574cc738335d5da8fc0dbf95cc1ba5772f2a23f77ea7763aa3')
+b2sums_i686=('311ca703d1b20745992a9cac9bfe6bf0220c1fac2403a4481d4ee43bb0a6e3c2be7e711792590ce6107830597d982ec0c7f5eb73d376ba0ced6ea917bf0dfbb8')
+b2sums_x86_64=('1a3c83d40ea954dae90cd0b4bc541ffe7bc6da6ac370f08e6154e751abe6b0750ddc827a777f01d095e18dab6ce330fc3931b7e5ee1c73c3200af120def0be21')
+b2sums_armv6h=('2702b9e16b5bc7c70ff7d42050384c1f68074d03b116aa2ff2dbaa1dd76575fe28ed2c245becb0246fa6e007e996e3bdac9f86bfafdd4a8479e48eb9bc37382b')
+b2sums_armv7h=('24f8a207ae431150a279be8d49ccd55a3f8fdf930606d78bcdc1403fba268e7c205d20d298dd041742bb049aae190f68b981e28e0ed10ec5fbe340f216dec3e4')
+b2sums_aarch64=('c1f05d32c979f6ea0bd300c915f2872588f5cac3b1d07398ec4989f129c87b13546fb68d80b4ef63852469d09d75381e914b310c3c2d622876afdde363524081')
latestver() {
local size ver

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 3
2026-10-01 00:02:06 Low 3
2026-09-30 00:20:07 Low 3
2026-09-29 00:07:46 Low 3
2026-09-28 00:28:32 Low 3
2026-09-27 01:16:09 Medium 2
2026-09-27 00:07:07 Low 3
2026-09-26 00:12:15 Low 3
2026-09-25 00:03:36 Low 3
2026-09-24 15:43:55 Medium 2
2026-09-24 00:24:14 Low 3
2026-09-23 01:39:21 Medium 2
2026-09-23 00:28:13 Low 3
2026-09-22 17:38:46 Medium 2
2026-09-22 13:37:53 Medium 2
2026-09-22 00:15:14 Low 3
2026-09-21 19:35:51 Medium 2
2026-09-21 13:34:51 Medium 2
2026-09-21 00:26:32 Low 3
2026-09-20 19:33:19 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion