tixati
maintainer goll
· 88 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a prebuilt binary tarball from the official project download host (download.tixati.com), which is plausibly project-owned; despite the non-whitelisted domain and skipped checksum for the .asc file, the primary payload is verified by a known PGP key and the source is not from a swappable personal host, limiting supply-chain risk.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt binary tarball from the official project download host (download.tixati.com), which is plausibly project-owned; despite the non-whitelisted domain and skipped checksum for the .asc file, the primary payload is verified by a known PGP key and the source is not from a swappable personal host, limiting supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source_i686=("https://download.tixati.com/${pkgname}-${pkgver}-1.i686.manualinstall.tar.gz"{,.asc})
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: goll <adrian.goll+aur[at]gmail>
2
3
pkgname=tixati
4
pkgver=3.44
5
pkgrel=1
6
pkgdesc="Tixati is a peer-to-peer file sharing program that uses the popular BitTorrent protocol"
7
arch=('i686' 'x86_64')
8
url='http://www.tixati.com/'
9
license=('custom:tixati')
10
depends=('gtk3' 'hicolor-icon-theme' 'dbus-glib' 'traceroute')
11
optdepends=('gconf: for shell integration')
12
source=('LICENSE')
13
source_i686=("https://download.tixati.com/${pkgname}-${pkgver}-1.i686.manualinstall.tar.gz"{,.asc})
14
source_x86_64=("https://download.tixati.com/${pkgname}-${pkgver}-1.x86_64.manualinstall.tar.gz"{,.asc})
15
sha256sums=('SKIP')
16
sha256sums_i686=('237467c8deec920a722d493766e1489fab31f00d080e8378f59a02f05ae12f94'
17
'SKIP')
18
sha256sums_x86_64=('3b060019a48eb7a9b7bd01460accebc4079e1a3105ea77ec66ccd7bc95f8911f'
19
'SKIP')
20
validpgpkeys=('9DEA5E350F9D285E46D3B7E3CE737F191AF5DCFB')
21
22
package() {
23
cd "$srcdir/$pkgname-${pkgver}-1.$CARCH.manualinstall"
24
install -Dm755 $pkgname "$pkgdir/usr/bin/$pkgname"
25
install -Dm644 $pkgname.png \
26
"$pkgdir/usr/share/icons/hicolor/48x48/apps/$pkgname.png"
27
install -Dm644 $pkgname.desktop \
28
"$pkgdir/usr/share/applications/$pkgname.desktop"
29
install -Dm644 ../LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
30
}
31
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |