xapian-tcl-bindings
maintainer orphaned
· 1 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a tarball from a non-whitelisted host, but it is the official release for the package and contains only buildable source code, not an executable payload; the risk is low as the worst case is source tampering, not remote code execution.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from a non-whitelisted host, but it is the official release for the package and contains only buildable source code, not an executable payload; the risk is low as the worst case is source tampering, not remote code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
source=(http://oligarchy.co.uk/xapian/${pkgver}/${_realname}-$pkgver.tar.xz)
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Albert Graef <aggraef@cmail.com>
2
# Contributor: Charles Goyard <cg@fsck.fr>
3
4
pkgname=xapian-tcl-bindings
5
_realname=xapian-bindings
6
pkgver=1.4.16
7
pkgrel=1
8
pkgdesc="Bindings allowing Xapian to be used from Tcl"
9
arch=(i686 x86_64)
10
url="http://xapian.org/docs/bindings/tcl/"
11
license=('GPL')
12
groups=(xapian)
13
# FIXME: tcllib isn't actually needed, but we pull it in to have the Tcl
14
# library path set up as needed. By installing into /usr/lib/tcllib, the
15
# package will hopefully work with whatever Tcl version happens to be
16
# installed.
17
depends=('tcl' 'tcllib' 'xapian-core')
18
source=(http://oligarchy.co.uk/xapian/${pkgver}/${_realname}-$pkgver.tar.xz)
19
md5sums=('333b7b2771dca0f07b092490468f75ef')
20
21
build() {
22
cd "$srcdir/${_realname}-$pkgver"
23
./configure --prefix=/usr --with-tcl TCL_LIB=/usr/lib/tcllib
24
make
25
}
26
27
package() {
28
cd "$srcdir/${_realname}-$pkgver"
29
make DESTDIR="$pkgdir" install
30
}
31
# vim:set ts=2 sw=2 et:
32
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |