veeam-nosnap
Downloads prebuilt RPMs from repository.veeam.com, which is Veeam's own official package repository infrastructure, with sha256 checksums provided; installing vendor-supplied proprietary binaries is a trust decision but not a supply-chain attack.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 80%): Downloads prebuilt RPMs from repository.veeam.com, which is Veeam's own official package repository infrastructure, with sha256 checksums provided; installing vendor-supplied proprietary binaries is a trust decision but not a supply-chain attack.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=("https://repository.veeam.com/backup/linux/agent-13/rpm/el/10/x86_64/veeam-nosnap-$pkgver-1.el10.x86_64.rpm"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Yegor Pomortsev <yegor@pomortsev.com>
# Contributors: krnlsoft <krnlsoft 4t hotmail d0t it>
# Contributors: theokonos
# Contributors: Ted Sadler
# Contributors: dekart811
# Contributors: CodeImp
pkgname=veeam-nosnap
pkgver=13.1.1.4
pkgrel=1
pkgdesc="Nosnap Veeam Agent for Linux"
arch=(x86_64)
url=https://www.veeam.com/products/downloads.html
install=${pkgname}.install
license=(custom:veeam)
depends=(ncurses lvm2 fuse mlocate)
conflicts=(veeam veeam-6)
options=(!strip)
source=("https://repository.veeam.com/backup/linux/agent-13/rpm/el/10/x86_64/veeam-nosnap-$pkgver-1.el10.x86_64.rpm"
"https://repository.veeam.com/backup/linux/agent-13/rpm/el/10/x86_64/veeam-libs-$pkgver-1.x86_64.rpm")
sha256sums=('03bc4b4710ec650ee03ce47bf303bd51125c0de464d8385142f9b9446e7afb67'
'90829a1d1dff15091245e1f672f40814006efdb46513631cbfe7dd804409b5c4')
noextract=("veeam-nosnap-$pkgver-1.el10.x86_64.rpm"
"veeam-libs-$pkgver-1.x86_64.rpm")
backup=('etc/veeam/veeam.ini'
'usr/share/veeam/lpb_scheme.sql'
'usr/share/veeam/db_upgrade.sql'
'usr/share/veeam/db_scheme.sql')
package() {
bsdtar -xf "$pkgname-$pkgver-1.el10.x86_64.rpm" -C "$pkgdir" -s /sbin/bin/ -s '|lib/systemd|usr/lib/systemd|'
bsdtar -xf "veeam-libs-$pkgver-1.x86_64.rpm" -C "$pkgdir" -s /sbin/bin/ -s '|lib/systemd|usr/lib/systemd|'
sed -i -e 's|# .include fipsmodule.cnf|.include /opt/veeam/veeamagentforlinux/openssl_fips_redistributable/3.1.2/ssl/fipsmodule.cnf|' \
"$pkgdir"/opt/veeam/veeamagentforlinux/openssl_fips_redistributable/3.1.2/ssl/openssl.cnf
sed -i -e 's|/var/run|/run|' -e 's|/sbin|/bin|' "$pkgdir"/usr/lib/systemd/system/veeamservice.service
rm -rf "$pkgdir"/usr/lib/.build-id/
install -dm755 "$pkgdir"/usr/share/licenses/$pkgname/
install -Dm644 "$pkgdir"/usr/share/veeam/EULA "$pkgdir"/usr/share/licenses/$pkgname/EULA
install -Dm644 "$pkgdir"/usr/share/veeam/3rdPartyNotices.txt "$pkgdir"/usr/share/licenses/$pkgname/3rdPartyNotices.txt
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |