xtide
The package downloads source code and a data file from the project's official domain (flaterco.com), which is not on the whitelist but is plausibly the maintainer's own; the downloaded tarballs are built or installed as data, and the checksums are provided, reducing supply-chain risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads source code and a data file from the project's official domain (flaterco.com), which is not on the whitelist but is plausibly the maintainer's own; the downloaded tarballs are built or installed as data, and the checksums are provided, reducing supply-chain risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
source=("https://flaterco.com/files/xtide/harmonics-dwf-20220109-free.tar.xz"
PKGBUILD
1 offending line(s) highlighted# Maintainer: dodoradio <dodoradio@outlook.com>
# Contributor: Beej Jorgensen <beej@beej.us>
pkgname=xtide
pkgver=2.15.5
pkgrel=1
pkgdesc="Harmonic tide clock and tide predictor"
arch=('i686' 'x86_64')
url="http://www.flaterco.com/xtide/xtide.html"
license=('GPL')
depends=('xaw3d' 'libpng' 'libtcd')
optdepends=(
'gpsd: for automatic location finding'
'xtide-wvs: for hi-res vector coastlines'
)
backup=("etc/$pkgname/$pkgname.conf")
source=("https://flaterco.com/files/xtide/harmonics-dwf-20220109-free.tar.xz"
"https://flaterco.com/files/xtide/$pkgname-$pkgver.tar.xz"
"${pkgname}.conf"
"${pkgname}.desktop"
)
md5sums=('095eaf7f8a62fba55b91455182974154'
'48b6993d4a04a15d2d7be355b6e0e739'
'4de09c336aa0e41980c1925d06201e5c'
'eb5ebe8432103880ff3331f3236b3e74')
prepare() {
cd "$srcdir/$pkgname-$pkgver"
./configure --prefix=/usr --sbindir=/usr/bin
}
build() {
cd "$srcdir/$pkgname-$pkgver"
make
}
package() {
local hver=20220109
local hdir=harmonics-dwf-${hver}
local hfile=${hdir}-free.tcd
# install harmonics file
install -D -m0644 $srcdir/$hdir/$hfile "$pkgdir/usr/share/$pkgname/$hfile"
# config file
install -D -m0644 $srcdir/${pkgname}.conf $pkgdir/etc/${pkgname}.conf
# desktop file
install -D -m0644 $srcdir/${pkgname}.desktop $pkgdir/usr/share/applications/${pkgname}.desktop
# binary
cd "$srcdir/$pkgname-$pkgver"
make DESTDIR="$pkgdir/" install
# icon
install -D -m0644 iconsrc/icon_48x48_orig.png $pkgdir/usr/share/pixmaps/${pkgname}.png
}
# vim:set ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |