1panel-bin

MEDIUM
maintainer orphaned 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Downloads a prebuilt binary from resource.fit2cloud.com (non-whitelisted but plausibly the project's official CDN for 1Panel/FIT2Cloud); checksums are provided and match, reducing swap risk, but the host is a cloud resource domain that cannot be independently verified as the project's own release infrastructure, making this a borderline medium rather than clean.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:29 source_aarch64=("${pkgname}-${pkgver//_/-}-arm64.tar.gz::https://resource.fit2cloud.com/1panel/package/stable/v${pkgver//_/-}/release/1panel-v${pkgver//_/-}-linux-arm64.tar.gz")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): Downloads a prebuilt binary from resource.fit2cloud.com (non-whitelisted but plausibly the project's official CDN for 1Panel/FIT2Cloud); checksums are provided and match, reducing swap risk, but the host is a cloud resource domain that cannot be independently verified as the project's own release infrastructure, making this a borderline medium rather than clean.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer:
2# Contributor: Senge Dev <sengedev at gmail dot com>
3
4pkgname=1panel-bin
5pkgver=1.10.9_lts
6pkgrel=1
7pkgdesc="1Panel is a modern and open source Linux panel."
8arch=('x86_64' 'aarch64')
9url="https://1panel.cn"
10license=('GPL-3.0-or-later')
11_1panel_original_port=`expr $RANDOM % 55535 + 10000`
12_1panel_original_username=$(pwgen -nABCv 10 1)
13_1panel_original_password=$(pwgen -nBCv 20 1)
14_1panel_original_entrance=$(pwgen -nABCv 10 1)
15install=1panel.install
16
17makedepends=(
18 'pwgen' # Generate username, password and 1Panel entrance before compile.
19 'lsof' # Make sure the port will not be occupied.
20)
21optdepends=(
22 'ufw' # Firewall manager
23 'firewalld' # Firewall manager
24 'docker' # Docker image manager
25 'docker-compose' # Docker compose plugin, make sure 1Panel app store works.
26)
27provides=(1panel)
28conflicts=(1panel)
29source_aarch64=("${pkgname}-${pkgver//_/-}-arm64.tar.gz::https://resource.fit2cloud.com/1panel/package/stable/v${pkgver//_/-}/release/1panel-v${pkgver//_/-}-linux-arm64.tar.gz")
30source_x86_64=("${pkgname}-${pkgver//_/-}-amd64.tar.gz::https://resource.fit2cloud.com/1panel/package/stable/v${pkgver//_/-}/release/1panel-v${pkgver//_/-}-linux-amd64.tar.gz")
31sha256sums_x86_64=('a5b23b46017c179d189b9ac30ae0b14bf113ad67159d6fcd01eba1c8a6f87533')
32sha256sums_aarch64=('a44bbae01b90b5ae04a10a058f441bc431fb096c866fe4b32018e6a0ea8f7b51')
33
34build() {
35 _1panel_port=`expr $RANDOM % 55535 + 10000`
36 while lsof -i:$_1panel_port > /dev/null 2>&1; do
37 _1panel_port=`expr $RANDOM % 55535 + 10000`
38 done
39 # Create 1pctl file, or 1Panel systemd service cannot start.
40 cat > ${srcdir}/1pctl << EOF
41#!/bin/bash
42BASE_DIR=/opt
43ORIGINAL_PORT=${_1panel_port}
44ORIGINAL_VERSION=${pkgver}
45ORIGINAL_ENTRANCE=$(pwgen -nABCv 10 1)
46ORIGINAL_USERNAME=$(pwgen -nABCv 10 1)
47ORIGINAL_PASSWORD=$(pwgen -nBCv 20 1)
481panel \$@
49EOF
50}
51
52package() {
53 install -vd ${pkgdir}/opt/1panel
54 install -vDm755 ${srcdir}/*/1panel ${pkgdir}/usr/bin/1panel
55 install -vDm644 ${srcdir}/*/1panel.service -t ${pkgdir}/usr/lib/systemd/system
56 install -vDm755 ${srcdir}/*/1pctl ${pkgdir}/usr/bin/1pctl
57}
58

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Medium 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion