symantec-ghost
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:20
'http://upload.wikimedia.org/wikipedia/en/5/58/Norton_Ghost_icon.png' -
PKGBUILD:21
'ftp://ftp.norton.com/public/english_us_canada/products/symantec_ghost_solution_suite/2.5/manuals/readme.txt'
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed it and judged it HIGH (confidence 72%): The FTP host ftp.norton.com is Symantec/Norton's own official public FTP server for product updates, so the supply-chain concern is a false positive. All sources have explicit SHA256 checksums. However, the PKGBUILD is broken: the ghost binary installed in package() is never extracted from GSSB2174.zip (no unzip/bsdtar call in prepare() or package()), and 'ghost' is not listed as a standalone source, so the build would fail. Additionally, packaging proprietary commercial Symantec Ghost software and linking its README as the license file raises a piracy concern, as this is paid commercial software being freely redistributed via AUR.
PKGBUILD
2 offending line(s) highlighted# Maintainer: Chris Severance aur.severach aATt spamgourmet dott com
# Contributor: N. Izumi izmntuk google email
set -u
pkgname='symantec-ghost'
pkgver='11.5'
pkgrel='2'
pkgdesc='Symantec Ghost for Linux'
arch=('i686' 'x86_64')
url='http://www.symantec.com/ghost-solution-suite'
license=('custom')
depends_x86_64=('lib32-gcc-libs' 'lib32-libx11')
depends_i686=('gcc-libs' 'libx11')
optdepends=('polkit: to run ghost directly from menu')
makedepends=('glibc')
options=('!strip')
source=(
'ghost.desktop'
'ghost.polkit'
'http://upload.wikimedia.org/wikipedia/en/5/58/Norton_Ghost_icon.png'
'ftp://ftp.norton.com/public/english_us_canada/products/symantec_ghost_solution_suite/2.5/manuals/readme.txt'
'ftp://ftp.norton.com/public/english_us_canada/products/symantec_ghost_solution_suite/2.5/updates/GSSB2174.zip'
)
#source[4]="${source[4]##*/}"
sha256sums=('7d0b4a0f3c15927d8b9c788f61ea05d6dd591fea0db99e8cb5cacaba5dab218c'
'852c2208a95080923e7534146e86d0b50ff790a254161fad900029c7e44181e3'
'849459ed3ff52e76547eb1f90d2963226a4bd9d9875473785cbf3922ab3ca0ac'
'39b5bca2401df511364904039fb8f692be3095f57df434245cfc36893416b176'
'a477be351ba22d7f11bbeebfa2a40cad81d394e6c0c95657e3e4d2705876b228')
prepare() {
set -u
iconv -f 'cp1251' -t 'utf8' 'readme.txt' -o 'README.txt'
cp --attributes-only --preserve='timestamps' 'readme.txt' 'README.txt'
set +u
}
package() {
set -u
install -Dpm744 'ghost' -t "${pkgdir}/usr/bin/"
install -Dpm644 'Norton_Ghost_icon.png' "${pkgdir}/usr/share/icons/ghost.png"
install -Dpm644 'ghost.desktop' -t "${pkgdir}/usr/share/application/"
install -Dpm644 'ghost.polkit' "${pkgdir}/usr/share/polkit-1/actions/org.archlinux.pkexec.ghost.policy"
install -Dpm644 'README.txt' "${pkgdir}/usr/share/doc/${pkgname}/README"
install -d "${pkgdir}/usr/share/licenses/${pkgname}"
ln -s "/usr/share/doc/${pkgname}/README" "${pkgdir}/usr/share/licenses/${pkgname}/COPYING"
set +u
}
set +u
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | HIGH | 2 |
| 2026-08-02 00:16:08 | HIGH | 2 |
| 2026-08-01 00:11:18 | HIGH | 2 |
| 2026-07-31 00:14:10 | HIGH | 2 |
| 2026-07-30 00:17:23 | HIGH | 2 |
| 2026-07-29 00:25:53 | HIGH | 2 |
| 2026-07-28 00:07:28 | HIGH | 2 |
| 2026-07-27 00:24:32 | HIGH | 2 |
| 2026-07-26 00:07:32 | HIGH | 2 |
| 2026-07-25 00:13:44 | HIGH | 2 |
| 2026-07-24 00:02:28 | HIGH | 2 |
| 2026-07-23 00:14:47 | HIGH | 2 |
| 2026-07-22 00:29:32 | HIGH | 2 |
| 2026-07-21 00:24:15 | HIGH | 2 |
| 2026-07-20 00:19:49 | HIGH | 2 |
| 2026-07-19 00:17:08 | HIGH | 2 |
| 2026-07-18 00:14:48 | HIGH | 2 |
| 2026-07-17 00:06:16 | HIGH | 2 |
| 2026-07-16 00:05:41 | HIGH | 2 |
| 2026-07-15 00:09:25 | HIGH | 2 |