ttf-xo-fonts
maintainer Drommer
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a font archive from the project's official domain myoffice.ru; fonts are static data files, not executable code, so the worst case of a swapped source is limited to display issues, not code execution.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a font archive from the project's official domain myoffice.ru; fonts are static data files, not executable code, so the worst case of a swapped source is limited to display issues, not code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("https://myoffice.ru/files/fonts/MyOffice_XO_Fonts_1.1.zip"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Serhii Starovoitov <drommer.94@gmail.com>
2
3
pkgname=ttf-xo-fonts
4
pkgver=1.1
5
pkgrel=1
6
epoch=1
7
pkgdesc='XO by MyOffice provide metric-compatible fonts with Microsoft to display documents without distortion and violation of the structure'
8
arch=('any')
9
url='https://myoffice.ru'
10
license=('custom')
11
provides=('ttf-font' 'ttf-xo-caliburn' 'ttf-xo-courser' 'ttf-xo-oriel' 'ttf-xo-symbol' 'ttf-xo-tahion' 'ttf-xo-thames' 'ttf-xo-trebizond' 'ttf-xo-verbena' 'ttf-xo-windy')
12
source=("https://myoffice.ru/files/fonts/MyOffice_XO_Fonts_1.1.zip"
13
"license.txt")
14
sha256sums=('9152219ce09626511f824be105f512e687604f0311c130f234c67bd1a7395fe9'
15
'a803b8232be71863ea0c36fc40b67a32aa9f4cd1a33fca01738a3727632e6f22')
16
17
package() {
18
install -Dm644 $srcdir/XO_Caliburn/XO_Caliburn/TTF/*.ttf -t $pkgdir/usr/share/fonts/XO/Caliburn
19
install -Dm644 $srcdir/XO_Courser/XO_Courser/TTF/*.ttf -t $pkgdir/usr/share/fonts/XO/Courser
20
install -Dm644 $srcdir/XO_Oriel/XO_Oriel/TTF/*.ttf -t $pkgdir/usr/share/fonts/XO/Oriel
21
install -Dm644 $srcdir/XO_Symbol/*.ttf -t $pkgdir/usr/share/fonts/XO
22
install -Dm644 $srcdir/XO_SymbolM/*.ttf -t $pkgdir/usr/share/fonts/XO
23
install -Dm644 $srcdir/XO_Tahion/XO_Tahion/TTF/*.ttf -t $pkgdir/usr/share/fonts/XO/Tahion
24
install -Dm644 $srcdir/XO_Thames/XO_Thames/TTF/*.ttf -t $pkgdir/usr/share/fonts/XO/Thames
25
install -Dm644 $srcdir/XO_Trebizond/*.ttf -t $pkgdir/usr/share/fonts/XO
26
install -Dm644 $srcdir/XO_Verbena/*.ttf -t $pkgdir/usr/share/fonts/XO
27
install -Dm644 $srcdir/XO_Windy/*.ttf -t $pkgdir/usr/share/fonts/XO
28
install -Dm644 $srcdir/license.txt -t $pkgdir/usr/share/licenses/${pkgname}
29
}
30
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |