tidb-bin

LOW
maintainer AstroProfundis 3 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads prebuilt binaries from PingCAP's official mirror domain (tiup-mirrors.pingcap.com), which is plausibly controlled by the project; despite the static analyzer flag for a non-standard host, the source is verifiable via checksums and the worst case of a malicious swap would be code execution, but the context suggests legitimate use of official infrastructure.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt binaries from PingCAP's official mirror domain (tiup-mirrors.pingcap.com), which is plausibly controlled by the project; despite the static analyzer flag for a non-standard host, the source is verifiable via checksums and the worst case of a malicious swap would be code execution, but the context suggests legitimate use of official infrastructure.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:23 source_x86_64=("https://tiup-mirrors.pingcap.com/tidb-v$_basever-linux-amd64.tar.gz"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Allen Zhong <pdev@zhoal.pw>
2# Maintainer: Liqueur Librazy <im@librazy.org>
3# Contributor: Jian Zeng <anonymousknight96@gmail.com>
4# Contributor: Xuanwo <xuanwo@archlinuxcn.org>
5pkgbase=tidb-bin
6_basever=8.5.7
7#_relver=-prega
8#pkgver=$_basever.$_relver
9pkgver=$_basever
10pkgrel=1
11pkgname=("${pkgbase}")
12pkgdesc="A distributed NewSQL database compatible with MySQL protocol"
13arch=('x86_64' 'aarch64')
14url="https://github.com/pingcap/tidb"
15license=('Apache-2.0')
16depends=('gcc-libs')
17conflicts=('tidb-bin-nightly' 'tidb' 'tikv' 'tikv-pd')
18options=('strip' 'debug')
19backup=(etc/tidb/tidb.toml
20 etc/tikv/tikv.toml
21 etc/pd/pd.toml
22)
23source_x86_64=("https://tiup-mirrors.pingcap.com/tidb-v$_basever-linux-amd64.tar.gz"
24 "https://tiup-mirrors.pingcap.com/tikv-v$_basever-linux-amd64.tar.gz"
25 "https://tiup-mirrors.pingcap.com/pd-v$_basever-linux-amd64.tar.gz")
26source_aarch64=("https://tiup-mirrors.pingcap.com/tidb-v$_basever-linux-arm64.tar.gz"
27 "https://tiup-mirrors.pingcap.com/tikv-v$_basever-linux-arm64.tar.gz"
28 "https://tiup-mirrors.pingcap.com/pd-v$_basever-linux-arm64.tar.gz")
29source=(pd.service
30 tidb.service
31 tikv.service
32 pd-sysusers.conf
33 pd-tmpfiles.conf
34 tidb-sysusers.conf
35 tidb-tmpfiles.conf
36 tikv-sysusers.conf
37 tikv-tmpfiles.conf
38 pd.toml
39 tidb.toml
40 tikv.toml)
41sha256sums=('b03d12f2f8d6eb2e9d654d6258ca39000225cdf1418840f7e35081631bc4d924'
42 '22318c19bb89ff5a0852df5186cc1496214cd49f2264192413a326d1e8c93dc9'
43 '870b8eaf83bc0d22b05b0f3a7890660e483cf77bb1d84bc50ad04fb23068cd8c'
44 '5edd250ba9e70a4f8d27581ed658f0fbfeca58ca62429dec12bb5fffc0919b67'
45 '15633aaa2d7726375112a1b5af88105878f09c176a542cde6d0e5f0c4eee4495'
46 '2b147d80985e714d5f861baf76591104c07058b9b6fa573bf0676d675cf8fc20'
47 '30ce83fbec8f102c30e438282bb5b18c026d08480f2386d68f1116c12481bf66'
48 '744b252e29099b0099dc41e30bc3badd33b3d661c7126af8044faa4fc2df8927'
49 '935291bac6a216c6f880df9bfaec8900266413bb202ac483e79f291e1f28e9f1'
50 '44de9aed72b8bc9156db354dcddfe0624f2fe4fc91e903fe64892913cae93e0f'
51 'f32709894c0d2c105a4398dcaf027f1cbdee359a2a6747f43cac819e9df25517'
52 '1c933198cd9b5611bd7d25f4f3501bd1b580bb35352f8d65bc1cef8588400d24')
53sha256sums_x86_64=('2bff9bad29fe8142cdf556f839dd99a07f51f205ade7662eb9431b2f359b0460'
54 '87bb39d4ae3b0c966a1600f903525d4afe8dafca3ad179fc86610e1288a58591'
55 '23a3601aa49a48d62156df1895f0af7089c5d602f70f0b6d659cfc4c0f26b845')
56sha256sums_aarch64=('0d14c986226bab1defba4d916b8a5c0e8842fe166a7faa3db2864f956ac85b3c'
57 '4379cf3607ae2f4b163f4710b23f6e00f74e835e35d48c3a8afd7d1a80ab9e60'
58 '2fa000801144cd65c91641fe3676fc45a6273a8deea8f776fc215c069748e589')
59
60_package() {
61 provides=("tidb-server=$_basever" "tikv-server=$_basever" "pd-server=$_basever")
62 install='tidb.install'
63
64 cd "$srcdir"
65
66 install -Dm644 pd-sysusers.conf "$pkgdir"/usr/lib/sysusers.d/pd.conf
67 install -Dm644 pd-tmpfiles.conf "$pkgdir"/usr/lib/tmpfiles.d/pd.conf
68 install -Dm644 tidb-sysusers.conf "$pkgdir"/usr/lib/sysusers.d/tidb.conf
69 install -Dm644 tidb-tmpfiles.conf "$pkgdir"/usr/lib/tmpfiles.d/tidb.conf
70 install -Dm644 tikv-sysusers.conf "$pkgdir"/usr/lib/sysusers.d/tikv.conf
71 install -Dm644 tikv-tmpfiles.conf "$pkgdir"/usr/lib/tmpfiles.d/tikv.conf
72
73 install -Dm644 pd.service "$pkgdir/usr/lib/systemd/system/pd.service"
74 install -Dm644 tidb.service "$pkgdir/usr/lib/systemd/system/tidb.service"
75 install -Dm644 tikv.service "$pkgdir/usr/lib/systemd/system/tikv.service"
76
77 install -Dm644 pd.toml "$pkgdir/etc/pd/pd.toml"
78 install -Dm644 tidb.toml "$pkgdir/etc/tidb/tidb.toml"
79 install -Dm644 tikv.toml "$pkgdir/etc/tikv/tikv.toml"
80
81 install -dm755 "$pkgdir"/etc/{pd,tidb,tikv}
82 install -dm755 "$pkgdir"/usr/bin
83 install -Dm755 {pd,tidb,tikv}-server "$pkgdir"/usr/bin
84}
85
86for _p in ${pkgname[@]}; do
87 eval "package_${_p}() {
88 $(declare -f "_package${_p#${pkgbase}}")
89 _package${_p#${pkgbase}}
90 }"
91done
92
93

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion