warp-terminal-autoup-bin
The package downloads a prebuilt Arch package from the official project domain (releases.warp.dev), which is a standard and trusted practice for distributing binaries; while the host is not on a typical whitelist, it is plausibly owned by the project, and the binary is extracted without further execution or modification, limiting risk to that of trusting the upstream vendor.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt Arch package from the official project domain (releases.warp.dev), which is a standard and trusted practice for distributing binaries; while the host is not on a typical whitelist, it is plausibly owned by the project, and the binary is extracted without further execution or modification, limiting risk to that of trusting the upstream vendor.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:33
"${_pkgname}-v${pkgver}-1-x86_64.pkg.tar.zst::https://releases.warp.dev/stable/v${pkgver}/${_pkgname}-v${pkgver}-1-x86_64.pkg.tar.zst"
PKGBUILD
1 offending line(s) highlightedpkgname=warp-terminal-autoup-bin
_pkgname=warp-terminal
pkgver=0.2026.08.18.02.52.stable_00
pkgrel=1
pkgdesc='Warp, the Rust-based terminal for developers and teams'
arch=('x86_64')
url='https://warp.dev'
license=('custom')
depends=(
'curl'
'default-cursors'
'fontconfig'
'libegl'
'libx11'
'libxcb'
'libxcursor'
'libxi'
'libxkbcommon-x11'
'opengl-driver'
'xdg-utils'
'zlib'
)
optdepends=(
'adwaita-cursors: for if there is no default cursor installed'
'zenity: for file dialogs in Gnome'
'kdialog: for file dialogs in KDE'
'org.freedesktop.secrets: for securely storing passwords'
)
provides=("${_pkgname}=${pkgver}")
conflicts=("${_pkgname}")
options=('!strip' '!debug')
source=(
"${_pkgname}-v${pkgver}-1-x86_64.pkg.tar.zst::https://releases.warp.dev/stable/v${pkgver}/${_pkgname}-v${pkgver}-1-x86_64.pkg.tar.zst"
)
noextract=("${_pkgname}-v${pkgver}-1-x86_64.pkg.tar.zst")
sha256sums=('fb9fa2b9ec4351872966ffad70517c5c552da6193c2540cf9d8595f321b0d468')
package() {
local _upstream_pkg="${_pkgname}-v${pkgver}-1-x86_64.pkg.tar.zst"
bsdtar \
--exclude '.BUILDINFO' \
--exclude '.MTREE' \
--exclude '.PKGINFO' \
-xpf "${srcdir}/${_upstream_pkg}" \
-C "${pkgdir}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 3 |
| 2026-09-01 00:11:19 | Low | 3 |
| 2026-08-31 00:19:57 | Low | 3 |
| 2026-08-30 00:04:14 | Low | 3 |
| 2026-08-29 00:29:17 | Low | 3 |