binance-app
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("binance-${pkgver}.deb::https://ftp.binance.com/electron-desktop/linux/production/binance-amd64-linux.deb")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt Electron binary .deb from ftp.binance.com, which is Binance's own official distribution host (the official Binance download page links to this same endpoint). However, there are two genuine concerns: (1) The URL is not versioned — it always resolves to 'latest' regardless of pkgver, meaning the sha256sum is the only integrity guard and will silently break on any upstream update, making the version field misleading and the package fragile. (2) A prebuilt, closed-source Electron binary from any host — even the vendor's own — constitutes an executed binary payload that cannot be audited, which is the canonical definition of a medium supply-chain risk in AUR context. The sha256sum does provide a pinned integrity check, which mitigates active substitution risk somewhat, but the non-versioned URL means future pkgrel bumps could ship a different binary than advertised. This is a real medium concern (unauditable executed binary from a vendor host with a mutable URL), not a false positive, but there is no evidence of malice.
PKGBUILD
1 offending line(s) highlighted# Maintainer: VirGuaZ <virguaz@proton.me>
# NOTE: Binance does not provide versioned download URLs.
# Version is verified via sha256sum against the official release.
pkgname=binance-app
pkgver=2.2.1
pkgrel=1
pkgdesc="Official Binance desktop application"
arch=('x86_64')
url="https://www.binance.com"
license=('custom')
depends=('gtk3' 'nss' 'alsa-lib' 'libxtst')
source=("binance-${pkgver}.deb::https://ftp.binance.com/electron-desktop/linux/production/binance-amd64-linux.deb")
sha256sums=('25cf4c8b76a56cbf879479bf2844e674078dea9cca3f0c72789f8c18bcb59a08')
package() {
cd "${srcdir}"
bsdtar -xf data.tar.* -C "${pkgdir}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |