storcli

LOW
maintainer k0ste 16 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads official Broadcom firmware tool archives from the vendor's own domain (broadcom.com), which is the legitimate source, despite the non-whitelisted subdomain; the content is verified via checksums and consists of prebuilt binaries for a hardware management CLI, not malicious code.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads official Broadcom firmware tool archives from the vendor's own domain (broadcom.com), which is the legitimate source, despite the non-whitelisted subdomain; the content is verified via checksums and consists of prebuilt binaries for a hardware management CLI, not malicious code.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source=("https://docs.broadcom.com/docs-and-downloads/host-bus-adapters/host-bus-adapters-common-files/sas_sata_nvme_12g_p${_phase}/${_name}${_phase}.zip"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Konstantin Shalygin <k0ste@k0ste.ru>
2# Contributor: Konstantin Shalygin <k0ste@k0ste.ru>
3
4pkgname='storcli'
5_name='STORCLI_SAS3.5_P'
6pkgver='007.3811.0000'
7pkgrel='1'
8_phase='39'
9_prefix='univ_viva_cli_rel/Unified_storcli_all_os'
10pkgdesc="CLI program for LSI MegaRAID cards"
11url='https://www.broadcom.com/'
12license=('custom')
13options=('!debug')
14arch=('x86_64' 'aarch64')
15makedepends=('libarchive')
16source=("https://docs.broadcom.com/docs-and-downloads/host-bus-adapters/host-bus-adapters-common-files/sas_sata_nvme_12g_p${_phase}/${_name}${_phase}.zip"
17 "https://docs.broadcom.com/docs-and-downloads/host-bus-adapters/host-bus-adapters-common-files/sas_sata_nvme_12g_p28/${_name}28.zip")
18sha256sums=('8487c1d099b451b2045e0d615cb081cba354891ee663cb30b621f2f51c94a40d'
19 'c15ef2d5b66f1d5988aa2bc318c49025f248d69058533e02a8f0acc86681cc85')
20
21_archstr=$([[ "${CARCH}" == 'x86_64' ]] && echo -n "Linux" || echo -n "ARM/Linux")
22_filearch=$([[ "${CARCH}" == 'x86_64' ]] && echo -n "noarch" || echo -n "${CARCH}")
23
24prepare() {
25 mkdir "${pkgname}_${pkgver}" "${pkgname}_legacy"
26 bsdtar -xf "${_name}${_phase}/${_prefix}/${_archstr}/${pkgname}-${pkgver}-1.${_filearch}.rpm" -C "${pkgname}_${pkgver}"
27# The legacy is version of software for support 9305 controllers, after this version the support of this controller is absent
28 bsdtar -xf "${_name}28/${_prefix}/${_archstr}/${pkgname}-007.2703.0000.0000-1.${_filearch}.rpm" -C "${pkgname}_legacy"
29}
30
31package() {
32 install -Dm0755 "${pkgname}_${pkgver}/opt/MegaRAID/${pkgname}/${pkgname}64" "${pkgdir}/usr/bin/${pkgname}"
33 install -Dm0755 "${pkgname}_legacy/opt/MegaRAID/${pkgname}/${pkgname}64" "${pkgdir}/usr/bin/${pkgname}-legacy"
34 install -Dm0755 -d "${pkgdir}/opt/MegaRAID/${pkgname}"
35 ln -s "/usr/bin/${pkgname}" "${pkgdir}/opt/MegaRAID/${pkgname}/${pkgname}"
36 ln -s "/usr/bin/${pkgname}" "${pkgdir}/opt/MegaRAID/${pkgname}/${pkgname}64"
37
38 install -Dm0644 "${_name}${_phase}/${_prefix}/ThirdPartyLicenseNotice.pdf" \
39 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.pdf"
40}
41

Changes since previous scan

--- PKGBUILD @ 2026-09-22 00:15
+++ PKGBUILD @ 2026-10-02 00:00
@@ -3,18 +3,19 @@
pkgname='storcli'
_name='STORCLI_SAS3.5_P'
-pkgver='007.3703.0000.0000'
+pkgver='007.3811.0000'
pkgrel='1'
-_phase='38'
+_phase='39'
_prefix='univ_viva_cli_rel/Unified_storcli_all_os'
pkgdesc="CLI program for LSI MegaRAID cards"
url='https://www.broadcom.com/'
license=('custom')
+options=('!debug')
arch=('x86_64' 'aarch64')
makedepends=('libarchive')
source=("https://docs.broadcom.com/docs-and-downloads/host-bus-adapters/host-bus-adapters-common-files/sas_sata_nvme_12g_p${_phase}/${_name}${_phase}.zip"
"https://docs.broadcom.com/docs-and-downloads/host-bus-adapters/host-bus-adapters-common-files/sas_sata_nvme_12g_p28/${_name}28.zip")
-sha256sums=('d0f6065d3ed2993d64eaa1df274f08c624d4dc61bcdd802a1afdb552f0b6b511'
+sha256sums=('8487c1d099b451b2045e0d615cb081cba354891ee663cb30b621f2f51c94a40d'
'c15ef2d5b66f1d5988aa2bc318c49025f248d69058533e02a8f0acc86681cc85')
_archstr=$([[ "${CARCH}" == 'x86_64' ]] && echo -n "Linux" || echo -n "ARM/Linux")

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 09:37:47 Medium 1
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion