zmeventnotification

maintainer Nocifer · 4 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads model files and configuration data from various hosts, including non-whitelisted ones like pjreddie.com and google-coral, but these are legitimate upstream sources for well-known ML models; the files are not executable code and are used purely for object detection, posing minimal security risk.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads model files and configuration data from various hosts, including non-whitelisted ones like pjreddie.com and google-coral, but these are legitimate upstream sources for well-known ML models; the files are not executable code and are used purely for object detection, posing minimal security risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:28 'https://pjreddie.com/media/files/yolov3.weights'

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Nocifer <apmichalopoulos at gmail dot com>
2
3pkgname=zmeventnotification
4pkgver=6.1.29.ga306ad2
5pkgrel=4
6pkgdesc='A machine learning powered, secure websocket & MQTT based event notification server for ZoneMinder'
7arch=('any')
8url='https://github.com/ZoneMinder/zmeventnotification'
9license=('GPL-2.0-only')
10depends=('opencv' 'perl-config-inifiles' 'perl-crypt-eksblowfish' 'perl-json' 'perl-lwp-protocol-https' 'perl-net-mqtt-simple'
11 'perl-net-websocket-server' 'python-face_recognition' 'python-gifsicle' 'python-imageio' 'python-imageio-ffmpeg'
12 'python-imutils' 'python-pyzm' 'python-requests' 'python-scikit-learn' 'python-shapely'
13 # ¯\_(ツ)_/¯
14 'python-mysql-connector' 'python-psutil' 'python-sqlalchemy' 'qt5-base'
15 # Uncomment the next line to enable support for the Google Coral Edge TPU
16 #'edgetpu_api'
17 )
18makedepends=('python-build' 'python-installer' 'python-setuptools' 'python-wheel')
19backup=('etc/zoneminder/zmeventnotification.ini'
20 'etc/zoneminder/secrets.ini'
21 'etc/zoneminder/objectconfig.ini'
22 'etc/zoneminder/es_rules.json')
23install=${pkgname}.install
24source=("https://github.com/ZoneMinder/${pkgname}/archive/a306ad2dbe87c5ace3d0ba89d9d4235fd489424b.zip"
25 'https://raw.githubusercontent.com/pjreddie/darknet/master/data/coco.names'
26 # YOLOv3
27 'https://raw.githubusercontent.com/pjreddie/darknet/master/cfg/yolov3.cfg'
28 'https://pjreddie.com/media/files/yolov3.weights'
29 # YOLOv3 Tiny
30 'https://raw.githubusercontent.com/pjreddie/darknet/master/cfg/yolov3-tiny.cfg'
31 'https://pjreddie.com/media/files/yolov3-tiny.weights'
32 # YOLOv4
33 'https://raw.githubusercontent.com/AlexeyAB/darknet/master/cfg/yolov4.cfg'
34 'https://github.com/AlexeyAB/darknet/releases/download/darknet_yolo_v3_optimal/yolov4.weights'
35 # YOLOv4 Tiny
36 'https://raw.githubusercontent.com/AlexeyAB/darknet/master/cfg/yolov4-tiny.cfg'
37 'https://github.com/AlexeyAB/darknet/releases/download/darknet_yolo_v4_pre/yolov4-tiny.weights'
38 # Google Coral Edge TPU
39 'https://dl.google.com/coral/canned_models/coco_labels.txt'
40 'https://github.com/google-coral/edgetpu/raw/master/test_data/ssd_mobilenet_v2_coco_quant_postprocess_edgetpu.tflite'
41 'https://github.com/google-coral/edgetpu/raw/master/test_data/ssd_mobilenet_v2_face_quant_postprocess_edgetpu.tflite'
42 'https://github.com/google-coral/test_data/raw/master/ssdlite_mobiledet_coco_qat_postprocess_edgetpu.tflite'
43 )
44b2sums=('90b1a42202bd3d9c7a07e808180a937c4a55e83f2bdf207b2955b01a5cfa0d8fafa1524983dc9a65457bea0b2d7b5219f543b9478c7245c4282051a43a6bee5a'
45 '0dedadffac9f2b7d2b0c685caf7a0e4755afa06931b3aa3aa9aeb6fa0ec5db4a9c3111092d1a35fb5f2311493d61ff7fc26de8dba7cee80806538af0a6f03566'
46 '6129ec17d519b025f338274eb4d373b0a93e9081ec06ac3fd3953280b6d5bd9a6cfa0ff4d3d1f88f61cfab9682e51a24d33811e9bdbab4f044ddfbb33c418ab5'
47 '7678167b299c8f3f458eefe1c5f58667585332d33fd3946993fc38d663dbd848f2a798092337f9d04720c0cbbfc2471571d5b82eb67e2b3440a025f531298011'
48 'bcaedf19ad7e55fbcce0382d42fcd4929fe82c05b792914aa3292841008960e2593bd860b9f2865ad4d81395bb6d84c6d8124d0038133b7e974f4b95daa78845'
49 'f98b3f35cd573de364094e43a754b407d2785dc3ed1c1760a1a91d8b3407f2fbf4a54123fe1d3f50cd29131a315064073a0b54bf86451e9616a25b0ac3a57575'
50 'aa6b8653bca9376e1ae265db35534d6db0a9cf1cb54b2ed061752041316561f114b5a25a1c367980071e4323935641e4e6af086e09ad0fb6276bfcc8894fd37e'
51 '235705d527e07d433965930bc9cf5e73cba26e23a1861ed6b3db37d88aa59656884622442987095df2127b03ad1006c84d2c9021e1586fccf3befd3d8f2b618c'
52 'f41fff69542a8f38cfbdb0456bb80a7dd6e6c635542c66f697dec1489861e911cc476274e5d0bbd7e00bf8ec20464a803e6e0802ce8a5ae7b71c63d02d230b3a'
53 'cfb4215d19cf7e759bb17a4afdba373d6bfec2c44e4c3212967abd697e5fcc6d3124c6fdc2484e38936ac66311378b8331d158284182a53aeed18635291c4ef7'
54 '2944afa72472e77d3eccb299d710bc3abfcd7e0cb194dfb279c966cc809b3e15ff36a94ce08828e04ef4bd34780532cffa222a976864110cf9e639cd0733c89a'
55 '8bbddb185fbfe8bfa01e4bd282d9f7875929be0d456e84cc3fd5aad51a47f32c54116a55b0c2c7ec1bad84ab11935f0b7f58b4a53295b056e9f25ed7fa6ede44'
56 'a18aad7db47aa1a54c37ba0fa2e773e94f4378e5826dd9c466e2082e962768fa7e5e704ca4702168b4271b03b112ad5a939056128ce5340baca1dc82f15b3434'
57 'f18412cf71a8383704923248c5034b20bb796360884b011bf8852062a99818cba6ad3c69cf9e7e97aa19f005f11eca6a0382a7a7cdf444c7a56da982f2cd7749')
58
59prepare() {
60 cd ${pkgname}-a306ad2dbe87c5ace3d0ba89d9d4235fd489424b
61
62 # Change the default upstream ZM address to match the one used by the ZoneMinder package
63 sed -i 's|https://portal/zm|http://localhost:8095|g' secrets.ini
64}
65
66build() {
67 cd ${pkgname}-a306ad2dbe87c5ace3d0ba89d9d4235fd489424b/hook
68
69 # Build the accompanying Python package zmes_hooks
70 python -m build --wheel --no-isolation
71}
72
73package() {
74 # Create the folder structure
75 install -dm755 ${pkgdir}/etc/zoneminder
76 install -dm755 ${pkgdir}/usr/bin
77 install -dm755 ${pkgdir}/var/lib/${pkgname}
78 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/bin
79 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/push
80 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/contrib
81 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/images
82 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/mlapi
83 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/known_faces
84 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/unknown_faces
85 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/models/yolov3
86 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/models/tinyyolov3
87 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/models/yolov4
88 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/models/tinyyolov4
89 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/models/coral_edgetpu
90 install -dm755 -o http -g http ${pkgdir}/var/lib/${pkgname}/misc
91
92 # Move the object recognition model files into place
93 install -m644 yolov3.cfg ${pkgdir}/var/lib/${pkgname}/models/yolov3
94 install -m644 coco.names ${pkgdir}/var/lib/${pkgname}/models/yolov3
95 install -m644 yolov3.weights ${pkgdir}/var/lib/${pkgname}/models/yolov3
96
97 install -m644 yolov3-tiny.cfg ${pkgdir}/var/lib/${pkgname}/models/tinyyolov3
98 install -m644 coco.names ${pkgdir}/var/lib/${pkgname}/models/tinyyolov3
99 install -m644 yolov3-tiny.weights ${pkgdir}/var/lib/${pkgname}/models/tinyyolov3
100
101 install -m644 yolov4.cfg ${pkgdir}/var/lib/${pkgname}/models/yolov4
102 install -m644 coco.names ${pkgdir}/var/lib/${pkgname}/models/yolov4
103 install -m644 yolov4.weights ${pkgdir}/var/lib/${pkgname}/models/yolov4
104
105 install -m644 yolov4-tiny.cfg ${pkgdir}/var/lib/${pkgname}/models/tinyyolov4
106 install -m644 coco.names ${pkgdir}/var/lib/${pkgname}/models/tinyyolov4
107 install -m644 yolov4-tiny.weights ${pkgdir}/var/lib/${pkgname}/models/tinyyolov4
108
109 install -m644 coco_labels.txt ${pkgdir}/var/lib/${pkgname}/models/coral_edgetpu/coco_indexed.names
110 install -m644 ssd_mobilenet_v2_coco_quant_postprocess_edgetpu.tflite ${pkgdir}/var/lib/${pkgname}/models/coral_edgetpu
111 install -m644 ssd_mobilenet_v2_face_quant_postprocess_edgetpu.tflite ${pkgdir}/var/lib/${pkgname}/models/coral_edgetpu
112 install -m644 ssdlite_mobiledet_coco_qat_postprocess_edgetpu.tflite ${pkgdir}/var/lib/${pkgname}/models/coral_edgetpu
113
114 # Move the rest of the files into place
115 cd ${pkgname}-a306ad2dbe87c5ace3d0ba89d9d4235fd489424b
116
117 install -m755 -o http -g http zmeventnotification.pl ${pkgdir}/usr/bin
118
119 install -m755 -o http -g http pushapi_plugins/pushapi_pushover.py ${pkgdir}/var/lib/${pkgname}/bin
120
121 install -m755 -o http -g http hook/zm_event_start.sh ${pkgdir}/var/lib/${pkgname}/bin
122 install -m755 -o http -g http hook/zm_event_end.sh ${pkgdir}/var/lib/${pkgname}/bin
123 install -m755 -o http -g http hook/zm_detect.py ${pkgdir}/var/lib/${pkgname}/bin
124 install -m755 -o http -g http hook/zm_train_faces.py ${pkgdir}/var/lib/${pkgname}/bin
125
126 install -m644 -o http -g http docs/guides/contrib_guidelines.rst ${pkgdir}/var/lib/${pkgname}/contrib
127 install -m755 -o http -g http contrib/* ${pkgdir}/var/lib/${pkgname}/contrib
128
129 install -m644 zmeventnotification.ini ${pkgdir}/etc/zoneminder/
130 install -m644 secrets.ini ${pkgdir}/etc/zoneminder/
131 install -m644 hook/objectconfig.ini ${pkgdir}/etc/zoneminder/
132 install -m644 es_rules.json ${pkgdir}/etc/zoneminder/
133
134 # Temp fix for hardcoded /zm/ links in the configuration files
135 ln -sf /etc/zoneminder ${pkgdir}/etc/zm
136
137 # Install the accompanying Python package zmes_hooks
138 cd hook
139 python -m installer --destdir="${pkgdir}" dist/*.whl
140}
141

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion