aspia-host-bin
The package downloads a prebuilt binary from a GitHub release, which is an official source but not the primary project domain; while the checksum is verified, the use of a third-party fork and binary distribution introduces a supply-chain risk if the source were compromised.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 90%): The package downloads a prebuilt binary from a GitHub release, which is an official source but not the primary project domain; while the checksum is verified, the use of a third-party fork and binary distribution introduces a supply-chain risk if the source were compromised.
PKGBUILD
# Maintainer: Andrey Kashlak <me@andreymal.org>
pkgname=aspia-host-bin
_pkgname=${pkgname%-bin}
pkgver=3.0.19
pkgrel=1
pkgdesc="Remote desktop control and file transfer tool (host, official binary)"
url="https://aspia.org/"
arch=(x86_64)
license=(GPL-3.0-only)
depends=(
dbus
glibc
hicolor-icon-theme
libgcc
libstdc++
pam
polkit
ttf-font
)
backup=(etc/pam.d/aspia-terminal)
provides=(aspia-host)
conflicts=(aspia-host)
options=(!debug !strip)
source=(aspia-terminal.pam)
source_x86_64=("https://github.com/dchapyshev/aspia/releases/download/v${pkgver}/${_pkgname}-${pkgver}-${arch}.deb")
sha256sums=('8e0aced1c552483f1df1fe8dd7de1c18435c0c397741a9f6f60d36ec5aae1466')
sha256sums_x86_64=('9d4d3cbffecf954f873df8e868d48fadb7a9d1fb98a98ab8fc7296d1e37b9f43')
package() {
cd "${srcdir}"
bsdtar -xzf data.tar.xz -C "${pkgdir}"
mkdir -p "${pkgdir}/etc/pam.d"
install -m 644 aspia-terminal.pam "${pkgdir}"/etc/pam.d/aspia-terminal
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-28 15:21:17 | Medium | 2 |