zoom
The package downloads a prebuilt binary from Zoom's official domain, which is a legitimate source despite not being on the analyzer's whitelist; the worst case of a swapped source would be code execution, but the host is plausibly official and under Zoom's control.
Triggered rules
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads a prebuilt binary from Zoom's official domain, which is a legitimate source despite not being on the analyzer's whitelist; the worst case of a swapped source would be code execution, but the host is plausibly official and under Zoom's control.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:26
source=("${pkgname}-${pkgver}.${_subver}_orig_x86_64.pkg.tar.xz"::"https://zoom.us/client/${pkgver}.${_subver}/zoom_x86_64.pkg.tar.xz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Gordian Edenhofer <gordian.edenhofer@gmail.com>
# Maintainer: Christian Heusel <christian@heusel.eu>
pkgname=zoom
pkgver=7.2.0
_subver=5705
pkgrel=1
pkgdesc="Video Conferencing and Web Conferencing Service"
arch=('x86_64')
license=('LicenseRef-zoom')
url="https://zoom.us/"
replaces=('zoom-libs-bin' 'zoom-libs')
depends=('fontconfig' 'glib2' 'libpulse' 'libsm' 'ttf-font' 'libx11' 'libxtst' 'libxcb'
'libxcomposite' 'libxfixes' 'libxi' 'libxcursor' 'libxkbcommon-x11' 'libxrandr'
'libxrender' 'libxshmfence' 'libxslt' 'mesa' 'nss' 'xcb-util-image'
'xcb-util-keysyms' 'xcb-util-cursor' 'dbus' 'libdrm' 'gtk3' 'xcb-util-wm')
optdepends=('pulseaudio-alsa: audio via PulseAudio'
'ibus: remote control'
'picom: extra compositor needed by some window managers for screen sharing'
'xcompmgr: extra compositor needed by some window managers for screen sharing'
'qt5-webengine: fallback for bundled qt'
'qt5-remoteobjects: fallback for bundled qt'
'noto-fonts-emoji: emojis'
)
options=(!strip)
source=("${pkgname}-${pkgver}.${_subver}_orig_x86_64.pkg.tar.xz"::"https://zoom.us/client/${pkgver}.${_subver}/zoom_x86_64.pkg.tar.xz")
sha512sums=('c2c5b523732505793689c354f2add4d170486554c105a5835eceb01e764448f4be0afdbbabe3f38851cc3de1f2186ecab469796884a757184f3f1aa5d9a5c91f')
package() {
cp -dpr --no-preserve=ownership opt usr "${pkgdir}"
}
Changes since previous scan
--- PKGBUILD @ 2026-07-22 00:29+++ PKGBUILD @ 2026-09-19 13:30@@ -2,8 +2,8 @@ # Maintainer: Christian Heusel <christian@heusel.eu> pkgname=zoom-pkgver=7.1.5-_subver=4332+pkgver=7.2.0+_subver=5705 pkgrel=1 pkgdesc="Video Conferencing and Web Conferencing Service" arch=('x86_64')@@ -24,7 +24,7 @@ ) options=(!strip) source=("${pkgname}-${pkgver}.${_subver}_orig_x86_64.pkg.tar.xz"::"https://zoom.us/client/${pkgver}.${_subver}/zoom_x86_64.pkg.tar.xz")-sha512sums=('d5ca18a754565c569825606646488f9b51b757685fb5788b2b327356a00489812f66582c6f6d8d4ea8d03ca1c6f036b271f74f1b97f3dc2dcc54a115e13aa484')+sha512sums=('c2c5b523732505793689c354f2add4d170486554c105a5835eceb01e764448f4be0afdbbabe3f38851cc3de1f2186ecab469796884a757184f3f1aa5d9a5c91f') package() { cp -dpr --no-preserve=ownership opt usr "${pkgdir}"Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-19 13:30:35 | Low | 2 |
| 2026-07-22 00:29:32 | Clean | 2 |
| 2026-07-21 13:17:02 | Low | 1 |
| 2026-07-21 00:24:15 | Low | 2 |
| 2026-07-20 00:19:49 | Low | 2 |
| 2026-07-19 00:17:08 | Low | 2 |
| 2026-07-18 00:14:48 | Low | 2 |
| 2026-07-17 00:06:16 | Low | 2 |
| 2026-07-16 00:05:41 | Low | 2 |
| 2026-07-15 00:09:25 | Low | 2 |
| 2026-07-14 00:09:48 | Low | 2 |
| 2026-07-13 00:19:36 | Low | 2 |
| 2026-07-12 00:27:26 | Low | 2 |
| 2026-07-11 00:25:18 | Low | 2 |
| 2026-07-10 00:20:30 | Low | 2 |
| 2026-07-09 00:22:38 | Low | 2 |
| 2026-07-08 00:26:52 | Low | 2 |
| 2026-07-07 00:22:52 | Low | 2 |
| 2026-07-06 00:10:58 | Low | 2 |
| 2026-07-05 00:27:08 | Low | 2 |