tinybpt-git
The non-standard host is used only to download a CA certificate (cacert.pem) from a well-known and trusted source (curl.se), which is safe and commonly used for SSL/TLS verification; the main code is built from a legitimate git repository under the maintainer's control.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The non-standard host is used only to download a CA certificate (cacert.pem) from a well-known and trusted source (curl.se), which is safe and commonly used for SSL/TLS verification; the main code is built from a legitimate git repository under the maintainer's control.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:30
"tinybpt_cacert.pem::https://curl.se/ca/cacert.pem"
PKGBUILD
1 offending line(s) highlighted# Maintainer: taotieren <admin@taotieren.com>
pkgname=tinybpt-git
pkgver=r28.b490fcc
pkgrel=2
epoch=
pkgdesc="Tinybpt (Tiny Buildroot Packaging Tool) 是一个 buildroot 的包管理工具,主要处理 buildroot 的包依赖关系,提供包的安装、卸载等功能。"
arch=($CARCH)
url="https://gitee.com/tinylab/buildroot-toolkit"
license=(GPL-2.0-or-later)
groups=()
provides=(${pkgname%-git})
conflicts=(${pkgname%-git})
depends=(
bash
gcc-libs
glibc
openssl
)
makedepends=(
git
cmake
nlohmann-json
ninja
)
optdepends=("buildroot-meta: dependency requirements for buildroot")
checkdepends=()
options=()
source=(${pkgname}::git+$url.git
"tinybpt_cacert.pem::https://curl.se/ca/cacert.pem"
"CMakeLists.patch"
)
noextract=()
sha256sums=('SKIP'
'a3f328c21e39ddd1f2be1cea43ac0dec819eaa20a90425d7da901a11531b3aa5'
'aef37c794e79637913ceb23a9a300c51cf4d3264ab48837c82209f4bf6c3cddb')
pkgver() {
cd "${srcdir}/${pkgname}"
(
set -o pipefail
git describe --long --tag --abbrev=7 2>/dev/null | sed 's/^v//g;s/\([^-]*-g\)/r\1/;s/-/./g' ||
printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
)
}
prepare() {
git -C "${srcdir}/${pkgname}" clean -dfx
cd "${srcdir}/${pkgname}"
patch -p1 <${srcdir}/CMakeLists.patch
}
build() {
cp -rv ${srcdir}/tinybpt_cacert.pem ${srcdir}/${pkgname}
# see:https://wiki.archlinux.org/title/CMake_package_guidelines
cmake -S ${pkgname} \
-DCMAKE_BUILD_TYPE=None \
-DCMAKE_INSTALL_PREFIX=/usr \
-Wno-dev \
-B build \
-G Ninja
ninja -C build
}
package() {
DESTDIR="${pkgdir}" ninja -C "${srcdir}"/build install
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |