veeamblksnap-dkms

LOW
maintainer ypomortsev 2 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads a source RPM from Veeam's official repository to extract kernel modules for DKMS; this is a legitimate use of an unwhitelisted but official vendor domain, and the source is verified via sha256sum.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source RPM from Veeam's official repository to extract kernel modules for DKMS; this is a legitimate use of an unwhitelisted but official vendor domain, and the source is verified via sha256sum.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source=("https://repository.veeam.com/backup/linux/agent-13/rpm/el/10/x86_64/blksnap-${pkgver}-1.noarch.rpm"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Yegor Pomortsev <yegor@pomortsev.com>
2# Contributors: krnlsoft <krnlsoft 4t hotmail d0t it>
3
4_pkgbase=blksnap
5_pkgname=veeam${_pkgbase}
6pkgname=${_pkgname}-dkms
7pkgver=13.1.1.4
8pkgrel=1
9pkgdesc="Veeam Agent for Linux kernel modules (DKMS)"
10arch=(x86_64)
11url=https://www.veeam.com/products/downloads.html
12license=(LicenseRef-GPL-2.0)
13depends=(dkms)
14conflicts=("${_pkgbase}")
15source=("https://repository.veeam.com/backup/linux/agent-13/rpm/el/10/x86_64/blksnap-${pkgver}-1.noarch.rpm"
16 'dkms.conf')
17sha256sums=('780d6cf653ae861370fcc0be6701f1d3dcd66ca6ba42d7146fa93cdf9ba72af4'
18 '21a182149740160df2d3475fad4142a08d8fc850e0234d32922472f7e4aa66fc')
19
20package() {
21 local target="${pkgdir}/usr/src/${_pkgname}-${pkgver}"
22 mkdir -p "${target}"
23
24 # Copy sources (including Makefile)
25 cp -r "${srcdir}/usr/src/${_pkgbase}-${pkgver}/." "${target}/"
26
27 # Copy dkms.conf
28 install -Dm644 dkms.conf "${target}/dkms.conf"
29
30 # Set name and version
31 sed -e "s/@_PKGBASE@/${_pkgname}/" \
32 -e "s/@PKGVER@/${pkgver}/" \
33 -i "${target}/dkms.conf"
34}
35

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion