aptible-cli

maintainer orphaned · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt Debian binary package (.deb) from an S3 bucket (omnibus-aptible-toolbelt.s3.amazonaws.com) and installs it directly onto the system. While this is the official Aptible toolbelt distribution host (Aptible is a real PaaS company and this is their official omnibus package), the concerns are: (1) it's a prebuilt binary blob, not source-compiled; (2) only an MD5 checksum is used for integrity verification — MD5 is cryptographically broken and provides weak assurance; (3) no GPG/PGP signature verification is performed; (4) the binary is a Debian package being extracted and installed on Arch Linux, which is non-standard and could include bundled libraries with vulnerabilities. The S3 bucket path structure ('master/194/pkg/') suggests a CI artifact path rather than a stable release URL, meaning the artifact could theoretically be replaced. The binary executes as a full omnibus package under /opt/aptible-toolbelt. This is a legitimate vendor distribution method but represents a real supply-chain risk due to lack of cryptographic signature verification and use of a mutable CI artifact URL with only MD5 integrity checking.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=("https://omnibus-aptible-toolbelt.s3.amazonaws.com/aptible/omnibus-aptible-toolbelt/master/194/pkg/aptible-toolbelt_0.16.3%2B20191024181014%7Eubuntu.16.04-1_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt Debian binary package (.deb) from an S3 bucket (omnibus-aptible-toolbelt.s3.amazonaws.com) and installs it directly onto the system. While this is the official Aptible toolbelt distribution host (Aptible is a real PaaS company and this is their official omnibus package), the concerns are: (1) it's a prebuilt binary blob, not source-compiled; (2) only an MD5 checksum is used for integrity verification — MD5 is cryptographically broken and provides weak assurance; (3) no GPG/PGP signature verification is performed; (4) the binary is a Debian package being extracted and installed on Arch Linux, which is non-standard and could include bundled libraries with vulnerabilities. The S3 bucket path structure ('master/194/pkg/') suggests a CI artifact path rather than a stable release URL, meaning the artifact could theoretically be replaced. The binary executes as a full omnibus package under /opt/aptible-toolbelt. This is a legitimate vendor distribution method but represents a real supply-chain risk due to lack of cryptographic signature verification and use of a mutable CI artifact URL with only MD5 integrity checking.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Frederick Zhang <frederick888@tsundere.moe>
2pkgname=aptible-cli
3pkgver=0.16.3
4pkgrel=2
5pkgdesc="The full stack of aptible-toolbelt"
6arch=('x86_64')
7url="https://www.aptible.com/support/toolbelt/"
8license=('MIT')
9groups=('aptible')
10options=('!strip')
11source=("https://omnibus-aptible-toolbelt.s3.amazonaws.com/aptible/omnibus-aptible-toolbelt/master/194/pkg/aptible-toolbelt_0.16.3%2B20191024181014%7Eubuntu.16.04-1_amd64.deb")
12md5sums=('87daeab4c03183476a4fd78f13ba603d')
13
14package() {
15 msg2 "Extracting data.tar.gz..."
16 tar xf data.tar.gz -C "$pkgdir/"
17 mkdir -p "$pkgdir/usr/bin"
18 ln -s /opt/aptible-toolbelt/bin/aptible "$pkgdir/usr/bin/aptible"
19}
20

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion