unifi

LOW
maintainer freswa 73 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The source is a prebuilt UniFi software package from dl.ui.com, the official vendor domain; despite not being on a whitelist, it is a legitimate and expected source for this software, with no code execution or supply-chain risks beyond standard trust in the vendor.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt UniFi software package from dl.ui.com, the official vendor domain; despite not being on a whitelist, it is a legitimate and expected source for this software, with no code execution or supply-chain risks beyond standard trust in the vendor.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:19 source=("UniFi-${pkgver}.zip::https://dl.ui.com/unifi/${pkgver}/UniFi.unix.zip"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Frederik Schwan <freswa at archlinux dot org>
2# Contributor: Sébastien "Seblu" Luttringer <seblu@archlinux.org>
3
4pkgname=unifi
5pkgver=10.6.101
6pkgrel=1
7pkgdesc='Centralized management system for Ubiquiti UniFi AP'
8arch=('x86_64' 'armv7h' 'aarch64')
9url='https://unifi-network.ui.com'
10# We are allowed to ship the software in our repository
11# https://mailman.archlinux.org/mailman/private/arch-dev/2014-August/015690.html
12license=('custom')
13depends=(
14 'fontconfig'
15 'java-runtime-headless=25'
16 'mongodb'
17)
18conflicts=('tomcat-native')
19source=("UniFi-${pkgver}.zip::https://dl.ui.com/unifi/${pkgver}/UniFi.unix.zip"
20 mongod
21 unifi.service
22 unifi.sysusers
23 unifi.tmpfiles
24 LICENSE)
25b2sums=('ff3a281ad3c117a5e8226de2b56262b8753d8ec3730f12a945617275f7979514e23d527e701a99ebeac21d814c8898c850dc103636799224177656b0dc326b86'
26 '2c8d535aabe8e738a9ba375fc4ab7aaa1713c9aefffc3e652fd49bc6288d0b7d24cae64d04ded5d5052486a377edca190818874a80bafb33cf2ac94742540106'
27 '753d4f24793ca65c9f554bedfbc22d6507474d835986cdba435538ec6518bd14769a64485a5f4bab1fc879378ff4c4b64ec323fa362dac32f739ed119cb2647c'
28 '5474a726a8a222f463f47cdca44988889406e2bee7b3c7875d45b20dc283d1d9737772d8cb63cd35c75517f3606feaadcf02c00b73e5bbab40f459d78d066c3e'
29 'bd254ddbd4b52acca50b41dffe7ae1e2e5250f15574fc371d36dc133215f3a268623b0b5b12e73932c856bf90a69a178ba91530ffa8b08c0da51f51911b2ef92'
30 '84f2a201143b3e44ba09d1009818db507d8f261d495a86ce239bcbacee059aad5c63af1b43638b126be743ff7c660f0871eb2b4efe2031e2f64bc23f172052e0')
31
32package() {
33 # lib
34 install -dm755 "${pkgdir}"/usr/lib/unifi
35 cp -r UniFi/{bin,dl,lib,webapps} "${pkgdir}"/usr/lib/unifi
36 case ${CARCH} in
37 x86_64)
38 rm -r "${pkgdir}"/usr/lib/unifi/lib/native/Linux/aarch64
39 ;;
40 aarch64)
41 rm -r "${pkgdir}"/usr/lib/unifi/lib/native/Linux/x86_64
42 ;;
43 *)
44 rm -r "${pkgdir}"/usr/lib/unifi/lib/native/Linux
45 ;;
46 esac
47
48 # fix incompatibility with mongodb >= 3.6
49 rm "${pkgdir}"/usr/lib/unifi/bin/mongod
50 install -Dm755 "${srcdir}"/mongod "${pkgdir}"/usr/lib/unifi/bin/mongod
51
52 # data
53 install -dm750 "${pkgdir}"/var/lib/unifi
54 for _d in {data,run,work}; do
55 ln -s ../../../var/lib/unifi/${_d} "${pkgdir}"/usr/lib/unifi/${_d}
56 done
57
58 # log
59 ln -s ../../../var/log/unifi "${pkgdir}"/usr/lib/unifi/logs
60
61 # readme
62 install -Dm644 UniFi/readme.txt "${pkgdir}"/usr/share/doc/${pkgname}/README
63
64 # license
65 install -Dm644 LICENSE "${pkgdir}"/usr/share/licenses/${pkgname}/LICENSE
66
67 # systemd
68 install -Dm644 ${pkgname}.service "${pkgdir}"/usr/lib/systemd/system/${pkgname}.service
69 install -Dm644 ${pkgname}.tmpfiles "${pkgdir}"/usr/lib/tmpfiles.d/${pkgname}.conf
70 install -Dm644 ${pkgname}.sysusers "${pkgdir}"/usr/lib/sysusers.d/${pkgname}.conf
71}
72

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 09:19:41 Medium 1
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion