zendrite

maintainer ZhangHua · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a git checkout from a project-owned host (codefloe.com) which is not on the whitelist but plausibly the maintainer's own; building from source is normal for AUR packages and the code is not executed remotely.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a git checkout from a project-owned host (codefloe.com) which is not on the whitelist but plausibly the maintainer's own; building from source is normal for AUR packages and the code is not executed remotely.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("git+https://codefloe.com/pat-s/zendrite.git#tag=v$pkgver"

PKGBUILD

1 offending line(s) highlighted
1pkgname=zendrite
2pkgver=3.1.0
3pkgrel=1
4pkgdesc="An opinionated fork of element-hq/dendrite"
5arch=(x86_64)
6url=https://zendrite.pat-s.me/
7license=("GPL-3.0-or-later OR LicenseRef-Element-Commercial-License")
8depends=(glibc)
9makedepends=(git go)
10optdepends=("postgresql>=12: Recommended database"
11 "nats-server: Use external nats server")
12install="$pkgname.install"
13source=("git+https://codefloe.com/pat-s/zendrite.git#tag=v$pkgver"
14 "$pkgname.service")
15sha256sums=('f53cd6e5eefd62e872bb34b641442500907b07c755e1fe8d9bd70c496e7f1f38'
16 '8eb2c645705cd432b6d16cda65f31f06fa97f513b9d3d90e4c6e5a87bfb39513')
17
18prepare() {
19 cd "$pkgname"
20 export GOPATH="$srcdir"
21 go mod download -modcacherw
22}
23build() {
24 cd "$pkgname"
25 export CGO_CPPFLAGS="${CPPFLAGS}"
26 export CGO_CFLAGS="${CFLAGS}"
27 export CGO_CXXFLAGS="${CXXFLAGS}"
28 export CGO_LDFLAGS="${LDFLAGS}"
29 export GOFLAGS="-buildmode=pie -mod=readonly -modcacherw"
30 export GOPATH="$srcdir"
31 go build -ldflags "-compressdwarf=false -linkmode external -bindnow -X codefloe.com/pat-s/zendrite/internal.version=$pkgver" \
32 -tags goolm -o bin/ ./cmd/...
33}
34package() {
35 cd "$pkgname"
36 find bin -mindepth 1 -maxdepth 1 -type f -executable \
37 -exec install -Dvm755 -t "$pkgdir/usr/bin/" {} +
38 for f in "$pkgdir/usr/bin/"*
39 do
40 basename="$(basename "$f")"
41 if [[ "$basename" != "$pkgname"* ]]
42 then
43 mv -v "$f" "$pkgdir/usr/bin/$pkgname-$basename"
44 fi
45 done
46 install -Dvm644 LICENSE-COMMERCIAL "$pkgdir/usr/share/licenses/$pkgname/LICENSE-COMMERCIAL"
47 install -Dvm644 "../$pkgname.service" "$pkgdir/usr/lib/systemd/system/$pkgname.service"
48 install -Dvm644 -t "$pkgdir/usr/share/doc/$pkgname/" "$pkgname-sample.yaml"
49}
50

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 03:47:03 MEDIUM 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion