ugee-tablet
maintainer kokononine
· 2 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a tarball from the official vendor's download domain, building the vendor's own software; the non-whitelisted host is plausibly part of the vendor's infrastructure, and the package installs only vendor-provided files without executing remote code.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the official vendor's download domain, building the vendor's own software; the non-whitelisted host is plausibly part of the vendor's infrastructure, and the package installs only vendor-provided files without executing remote code.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:9
source=("https://download.ugee.com.cn/upload/download/$_pkgver_sub1/ugeeTablet-$pkgver-$_pkgver_sub2.tar.gz")
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: kokononine <nine_9@outlook.jp>
2
pkgname=ugee-tablet
3
pkgver=4.3.4
4
_pkgver_sub1=20241217
5
_pkgver_sub2=241031
6
pkgrel=2
7
pkgdesc='Ugee Tablet Driver(version 4.x)'
8
url='https://www.ugee.com.cn/download/'
9
source=("https://download.ugee.com.cn/upload/download/$_pkgver_sub1/ugeeTablet-$pkgver-$_pkgver_sub2.tar.gz")
10
arch=('x86_64')
11
license=('custom: commercial')
12
depends=()
13
#depends=('libx11' 'libxrender' 'libxrandr' 'libxinerama' 'libxtst' 'libsm' 'libice' 'libglvnd' 'libusb' 'freetype2' 'qt5-x11extras' 'hicolor-icon-theme')
14
optdepends=()
15
conflicts=()
16
provides=()
17
#options=()
18
install="PKGBUILD"
19
sha256sums=('83c51feb0d0a1e68e7f443665a68c8dab1fb41c72ec993c045ee465f839dd2ff')
20
21
package()
22
{
23
install -d "$pkgdir/usr"
24
install -d "$pkgdir/usr/lib"
25
install -d "$pkgdir/etc"
26
27
cp -r "$srcdir/ugeeTablet-$pkgver-$_pkgver_sub2/App/usr" "$pkgdir"
28
cp -r "$srcdir/ugeeTablet-$pkgver-$_pkgver_sub2/App/lib" "$pkgdir/usr"
29
cp -r "$srcdir/ugeeTablet-$pkgver-$_pkgver_sub2/App/etc" "$pkgdir"
30
}
31
32
post_install()
33
{
34
echo -en ":: \033[1m\033[33mA reboot is required after the installation!\033[0m\n"
35
}
36
37
post_upgrade()
38
{
39
post_install
40
}
41
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |