big-yotta

maintainer alex.henrie · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The package downloads a prebuilt binary RPM directly from sequencing.com (the upstream vendor's own domain, matching the package URL), extracts it, and installs the binaries. This is the official vendor host, not a personal or unofficial mirror, so the cheaper model's concern about 'non-standard host' is somewhat overstated. However, the core supply-chain concern remains valid: a closed-source, prebuilt binary blob is being installed with no ability to audit the build process, and the binary runs with user privileges. The sha256sum provides integrity but not authenticity (no GPG signature verification). This is a classic medium-risk pattern for AUR packages that wrap proprietary vendor binaries — not clearly malicious, but a real supply-chain trust concern since users must fully trust sequencing.com's binary distribution. Rating stays MEDIUM.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=('https://sequencing.com/sites/default/files/big-yotta-rpm-v5_3.rpm')
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The package downloads a prebuilt binary RPM directly from sequencing.com (the upstream vendor's own domain, matching the package URL), extracts it, and installs the binaries. This is the official vendor host, not a personal or unofficial mirror, so the cheaper model's concern about 'non-standard host' is somewhat overstated. However, the core supply-chain concern remains valid: a closed-source, prebuilt binary blob is being installed with no ability to audit the build process, and the binary runs with user privileges. The sha256sum provides integrity but not authenticity (no GPG signature verification). This is a classic medium-risk pattern for AUR packages that wrap proprietary vendor binaries — not clearly malicious, but a real supply-chain trust concern since users must fully trust sequencing.com's binary distribution. Rating stays MEDIUM.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Alex Henrie <alexhenrie24@gmail.com>
2pkgname=big-yotta
3pkgver=5.3
4pkgrel=1
5pkgdesc='Sequencing.com utility for uploading large genetic data files'
6arch=(x86_64)
7url='https://sequencing.com/big-yotta-dna-genome-file-uploader'
8license=('custom:big-yotta')
9source=('https://sequencing.com/sites/default/files/big-yotta-rpm-v5_3.rpm')
10sha256sums=('42c30b857891f8443dae24e22826f8bc244ef6d93bbe0d6c7d8d5d5a20a6e6ce')
11
12package() {
13 cp -r opt "$pkgdir"
14 install -Dm644 opt/BigYotta/BigYotta.desktop "$pkgdir/usr/share/applications/BigYotta.desktop"
15}
16

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion