xrt-bin
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The source URL is on xilinx.com, the official Xilinx/AMD vendor domain, so this is not an unofficial or personal host. The query-parameter style URL (openDownload?filename=...) is Xilinx's standard download redirect mechanism used across their product line — the actual filename is embedded in the parameter and is specific and versioned (xrt_202110.2.11.634_20.04-amd64-xrt.deb). An md5sum is provided, which pins the content at package-build time (though MD5 is weak, it still provides basic integrity verification). The package installs a prebuilt Debian binary from the official vendor, which is a legitimate but non-ideal packaging pattern (prebuilt binary vs. building from source). The main concerns are: (1) MD5 is cryptographically weak; (2) the dynamic URL could theoretically serve different content if Xilinx changes the backend, but the md5sum mitigates this; (3) no GPG signature verification. These are sloppy/non-standard practices but not a genuine supply-chain attack vector given the official vendor origin and checksum presence. The 'broken' flag is borderline since the package() function references data.tar.gz without extracting it from the .deb first (missing ar extraction step), but this is a packaging bug rather than a security issue. Overall: low severity, sloppy packaging.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source=(https://www.xilinx.com/bin/public/openDownload?filename=xrt_202110.2.11.634_20.04-amd64-xrt.deb)
PKGBUILD
1 offending line(s) highlightedpkgname=xrt-bin
pkgver=2021.2
pkgrel=1
pkgdesc="Xilinx Run Time for FPGA"
arch=('x86_64')
url="https://github.com/Xilinx/XRT"
license=('EULA')
groups=('base-devel')
depends=(ocl-icd)
optdepends=(vivado)
source=(https://www.xilinx.com/bin/public/openDownload?filename=xrt_202110.2.11.634_20.04-amd64-xrt.deb)
md5sums=(a40f8a4386e8f92f9af43d1bfae54b62)
package() {
tar -zxf data.tar.gz -C "${pkgdir}"
mv "${pkgdir}/lib" "${pkgdir}/usr/lib"
mv "${pkgdir}/opt/xilinx" "${pkgdir}/opt/Xilinx"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |