sbd
The source is a tarball from packetstormsecurity.net, a well-known and trusted security resource; the package builds from official source code and installs only the resulting binary and documentation, posing no execution of remote code or supply-chain risks.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from packetstormsecurity.net, a well-known and trusted security resource; the package builds from official source code and installs only the resulting binary and documentation, posing no execution of remote code or supply-chain risks.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("https://dl.packetstormsecurity.net/UNIX/netcat/${pkgname}-${pkgver}.tar.gz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Chris Severance aur.severach AatT spamgourmet.com
# Contributor: fnord0 <fnord0 AT riseup DOT net>
set -u
pkgname='sbd'
pkgver='1.36'
pkgrel='2'
pkgdesc='Netcat-clone, portable, offers strong encryption - features AES-128-CBC + HMAC-SHA1 encryption, program execution (-e), choosing source port, continuous reconnection with delay + more'
url='https://packetstormsecurity.com/UNIX/netcat/'
arch=('i686' 'x86_64')
license=('GPL')
source=("https://dl.packetstormsecurity.net/UNIX/netcat/${pkgname}-${pkgver}.tar.gz")
sha256sums=('a15ce468e7e04cc12fe2686e0a44e1201d7c67986681d51e255cba9362ab0676')
DLAGENTS=('https::/usr/bin/curl -kfLC - --retry 3 --retry-delay 3 -o %o %u') # from /etc/makepkg.conf, https://bbs.archlinux.org/viewtopic.php?id=143333
build() {
cd "${srcdir}/${pkgname}-${pkgver}"
make -s unix
}
package() {
set -u
cd "${srcdir}/${pkgname}-${pkgver}"
install -d "${pkgdir}/usr/bin"
install -d "${pkgdir}/usr/share/${pkgname}/doc"
install -d "${pkgdir}/usr/share/licenses/${pkgname}"
install -Dpm755 "${srcdir}/${pkgname}-${pkgver}/${pkgname}" -t "${pkgdir}/usr/share/${pkgname}/"
# We don't want the Windows binaries
#install -Dpm755 "${srcdir}/${pkgname}-${pkgver}/binaries/${pkgname}.exe" -t "${pkgdir}/usr/share/${pkgname}/"
#install -Dpm755 "${srcdir}/${pkgname}-${pkgver}/binaries/${pkgname}bg.exe" -t "${pkgdir}/usr/share/${pkgname}/"
install -Dpm644 "README" -t "${pkgdir}/usr/share/${pkgname}/doc/"
install -Dpm644 "CHANGES" -t "${pkgdir}/usr/share/${pkgname}/doc/"
install -Dpm644 "COPYING" -t "${pkgdir}/usr/share/licenses/${pkgname}/"
ln -sf "/usr/share/${pkgname}/${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
#ln -sf "/usr/share/${pkgname}/${pkgname}.exe" "${pkgdir}/usr/bin/${pkgname}.exe"
#ln -sf "/usr/share/${pkgname}/${pkgname}bg.exe" "${pkgdir}/usr/bin/${pkgname}bg.exe"
# Ensure there are no forbidden paths (git-aurcheck)
! grep -alqr "/sbin" "${pkgdir}" || echo "${}"
! grep -alqr "/usr/tmp" "${pkgdir}" || echo "${}"
! test -d "${pkgdir}/usr/sbin" || echo "${}"
set +u
}
set +u
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |