riseup-vpn-git

MEDIUM
maintainer kalikaneko 6 votes scanned 2026-10-05 23:40:58.404909
View on AUR
Why flagged

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 "git+https://0xacab.org/leap/bitmask-vpn.git"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Pea <peanut2 [aaaaat] systemli [dooot] org>
2pkgname=riseup-vpn-git
3pkgrel=1
4pkgver=0.25.8.r25.gdc7f2ee4
5pkgdesc="RiseupVPN is a branded build of Bitmask VPN. Bitmask VPN is a minimal rewrite of the Bitmask VPN Client, written in golang, that for now lacks client authentication, and is preconfigured to use a single provider."
6url="https://0xacab.org/leap/bitmask-vpn"
7arch=('x86_64')
8license=('GPL-3.0-only')
9conflicts=('riseup-vpn')
10source=(
11 "git+https://0xacab.org/leap/bitmask-vpn.git"
12 "riseup-vpn_launcher.desktop"
13 "riseup-vpn.png"
14)
15
16sha256sums=('SKIP'
17 'e21a0d99dcea6b849f80960fccc488e6294e3e794b0033fdc163291ecc8595ff'
18 '18cdea88cb7feb3de898918a78f612318b066d18c174d2a9addaa448f58de15c')
19
20pkgver() {
21 cd "bitmask-vpn"
22 git describe --long | sed 's/\([^-]*-g\)/r\1/;s/-/./g'
23}
24
25makedepends=(
26 'git'
27 'cmake'
28 'make'
29 'which'
30 'gcc'
31 'go'
32)
33
34depends=(
35 'qt6-base'
36 'qt6-tools'
37 'qt6-declarative'
38 'qt6-svg'
39 'openvpn'
40 'python'
41 'lxsession'
42)
43
44prepare() {
45 cd "bitmask-vpn"
46 sed -i 's@/usr/sbin/bitmask-root@/usr/bin/bitmask-root@g' pkg/pickle/helpers.go
47 sed -i 's@/usr/sbin/bitmask-root@/usr/bin/bitmask-root@g' pkg/launcher/launcher_linux.go
48 sed -i 's@/usr/sbin/bitmask-root@/usr/bin/bitmask-root@g' pkg/pickle/helpers/bitmask-root
49 sed -i 's@/usr/sbin/bitmask-root@/usr/bin/bitmask-root@g' helpers/se.leap.bitmask.policy
50}
51
52build() {
53 cd "bitmask-vpn"
54 export CGO_CPPFLAGS="${CPPFLAGS}"
55 export CGO_CFLAGS="${CFLAGS}"
56 export CGO_CXXFLAGS="${CXXFLAGS}"
57 export CGO_LDFLAGS="${LDFLAGS}"
58 export GOFLAGS="-buildmode=pie -trimpath -ldflags=-linkmode=external -mod=readonly -modcacherw"
59
60 PROVIDER=riseup make vendor
61 PROVIDER=riseup LRELEASE=/usr/lib/qt6/bin/lrelease RELEASE=yes make build
62}
63
64check() {
65 cd "bitmask-vpn"
66 CI="dont run integration tests as they are broken" make test
67}
68
69package() {
70 install -Dm644 riseup-vpn_launcher.desktop "${pkgdir}/usr/share/applications/riseup-vpn_launcher.desktop"
71 install -Dm644 riseup-vpn.png "${pkgdir}/usr/share/icons/hicolor/128x128/apps/riseup-vpn.png"
72
73 cd "bitmask-vpn"
74 install -Dm755 helpers/bitmask-root "${pkgdir}/usr/bin/bitmask-root"
75 install -Dm644 helpers/se.leap.bitmask.policy "${pkgdir}/usr/share/polkit-1/actions/se.leap.bitmask.policy"
76 install -Dm755 build/qt/release/riseup-vpn "${pkgdir}/usr/bin/riseup-vpn"
77}
78
79

Changes since previous scan

--- PKGBUILD @ 2026-06-19 19:07
+++ PKGBUILD @ 2026-10-05 23:40
@@ -5,7 +5,7 @@
pkgdesc="RiseupVPN is a branded build of Bitmask VPN. Bitmask VPN is a minimal rewrite of the Bitmask VPN Client, written in golang, that for now lacks client authentication, and is preconfigured to use a single provider."
url="https://0xacab.org/leap/bitmask-vpn"
arch=('x86_64')
-license=('GPL3')
+license=('GPL-3.0-only')
conflicts=('riseup-vpn')
source=(
"git+https://0xacab.org/leap/bitmask-vpn.git"

Scan history

Scanned at (UTC)SeverityRules
2026-10-05 23:40:58 Medium 1
2026-06-19 19:07:35 Clean 2
2026-06-18 16:11:54 Medium 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion