zendrite
maintainer ZhangHua
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a git checkout from a project-owned host (codefloe.com) which is not on the whitelist but plausibly the maintainer's own; building from source is normal for AUR packages and the code is not executed remotely.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a git checkout from a project-owned host (codefloe.com) which is not on the whitelist but plausibly the maintainer's own; building from source is normal for AUR packages and the code is not executed remotely.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("git+https://codefloe.com/pat-s/zendrite.git#tag=v$pkgver"
PKGBUILD
1 offending line(s) highlighted
1
pkgname=zendrite
2
pkgver=3.1.0
3
pkgrel=1
4
pkgdesc="An opinionated fork of element-hq/dendrite"
5
arch=(x86_64)
6
url=https://zendrite.pat-s.me/
7
license=("GPL-3.0-or-later OR LicenseRef-Element-Commercial-License")
8
depends=(glibc)
9
makedepends=(git go)
10
optdepends=("postgresql>=12: Recommended database"
11
"nats-server: Use external nats server")
12
install="$pkgname.install"
13
source=("git+https://codefloe.com/pat-s/zendrite.git#tag=v$pkgver"
14
"$pkgname.service")
15
sha256sums=('f53cd6e5eefd62e872bb34b641442500907b07c755e1fe8d9bd70c496e7f1f38'
16
'8eb2c645705cd432b6d16cda65f31f06fa97f513b9d3d90e4c6e5a87bfb39513')
17
18
prepare() {
19
cd "$pkgname"
20
export GOPATH="$srcdir"
21
go mod download -modcacherw
22
}
23
build() {
24
cd "$pkgname"
25
export CGO_CPPFLAGS="${CPPFLAGS}"
26
export CGO_CFLAGS="${CFLAGS}"
27
export CGO_CXXFLAGS="${CXXFLAGS}"
28
export CGO_LDFLAGS="${LDFLAGS}"
29
export GOFLAGS="-buildmode=pie -mod=readonly -modcacherw"
30
export GOPATH="$srcdir"
31
go build -ldflags "-compressdwarf=false -linkmode external -bindnow -X codefloe.com/pat-s/zendrite/internal.version=$pkgver" \
32
-tags goolm -o bin/ ./cmd/...
33
}
34
package() {
35
cd "$pkgname"
36
find bin -mindepth 1 -maxdepth 1 -type f -executable \
37
-exec install -Dvm755 -t "$pkgdir/usr/bin/" {} +
38
for f in "$pkgdir/usr/bin/"*
39
do
40
basename="$(basename "$f")"
41
if [[ "$basename" != "$pkgname"* ]]
42
then
43
mv -v "$f" "$pkgdir/usr/bin/$pkgname-$basename"
44
fi
45
done
46
install -Dvm644 LICENSE-COMMERCIAL "$pkgdir/usr/share/licenses/$pkgname/LICENSE-COMMERCIAL"
47
install -Dvm644 "../$pkgname.service" "$pkgdir/usr/lib/systemd/system/$pkgname.service"
48
install -Dvm644 -t "$pkgdir/usr/share/doc/$pkgname/" "$pkgname-sample.yaml"
49
}
50
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 03:47:03 | MEDIUM | 1 |