reed-alert-git

maintainer ganymede · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a git repository from a personal domain, which is not on a standard forge but plausibly the project's own; building from source is normal for AUR and the package installs only compiled artifacts and documentation, with no evidence of malicious payloads or remote code execution.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The source is a git repository from a personal domain, which is not on a standard forge but plausibly the project's own; building from source is normal for AUR and the package installs only compiled artifacts and documentation, with no evidence of malicious payloads or remote code execution.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source=('git://bitreich.org/reed-alert')

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Ganymede < ganymede _AT_ analogon _DOT_ eu>
2
3pkgname=reed-alert-git
4_pkgname=reed-alert
5pkgver=r88.b9d5e56
6pkgver() {
7 cd "$_pkgname"
8 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short HEAD)"
9}
10pkgrel=1
11pkgdesc="reed-alert is a small and simple monitoring tool for your server, written in Common Lisp"
12arch=('any')
13optdepends=('ecl' 'sbcl')
14url="https://dataswamp.org/~solene/2018-01-17-reed-alert.html"
15license=('custom')
16source=('git://bitreich.org/reed-alert')
17md5sums=('SKIP')
18install=reed-alert-git.install
19
20build() {
21 cd "$_pkgname"
22 sed -i -e 's:/usr/local:/usr:' Makefile
23 sed -i -e 's/-o root -g bin//' Makefile
24 sed -i -e 's/-o root -g wheel//' Makefile
25 make
26}
27
28package() {
29 cd "$_pkgname"
30 make DESTDIR="$pkgdir" install
31 install -Dm644 LICENSE "$pkgdir"/usr/share/licenses/$pkgname/LICENSE
32 install -Dm644 README "$pkgdir"/usr/share/doc/$pkgname/README
33 install -Dm644 example-full.lisp "$pkgdir"/usr/share/doc/$pkgname/example-full.lisp
34 install -Dm644 example-simple.lisp "$pkgdir"/usr/share/doc/$pkgname/example-simple.lisp
35}
36

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion