binance-app

maintainer VirGuaZ · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt Electron binary .deb from ftp.binance.com, which is Binance's own official distribution host (the official Binance download page links to this same endpoint). However, there are two genuine concerns: (1) The URL is not versioned — it always resolves to 'latest' regardless of pkgver, meaning the sha256sum is the only integrity guard and will silently break on any upstream update, making the version field misleading and the package fragile. (2) A prebuilt, closed-source Electron binary from any host — even the vendor's own — constitutes an executed binary payload that cannot be audited, which is the canonical definition of a medium supply-chain risk in AUR context. The sha256sum does provide a pinned integrity check, which mitigates active substitution risk somewhat, but the non-versioned URL means future pkgrel bumps could ship a different binary than advertised. This is a real medium concern (unauditable executed binary from a vendor host with a mutable URL), not a false positive, but there is no evidence of malice.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("binance-${pkgver}.deb::https://ftp.binance.com/electron-desktop/linux/production/binance-amd64-linux.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt Electron binary .deb from ftp.binance.com, which is Binance's own official distribution host (the official Binance download page links to this same endpoint). However, there are two genuine concerns: (1) The URL is not versioned — it always resolves to 'latest' regardless of pkgver, meaning the sha256sum is the only integrity guard and will silently break on any upstream update, making the version field misleading and the package fragile. (2) A prebuilt, closed-source Electron binary from any host — even the vendor's own — constitutes an executed binary payload that cannot be audited, which is the canonical definition of a medium supply-chain risk in AUR context. The sha256sum does provide a pinned integrity check, which mitigates active substitution risk somewhat, but the non-versioned URL means future pkgrel bumps could ship a different binary than advertised. This is a real medium concern (unauditable executed binary from a vendor host with a mutable URL), not a false positive, but there is no evidence of malice.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: VirGuaZ <virguaz@proton.me>
2
3# NOTE: Binance does not provide versioned download URLs.
4# Version is verified via sha256sum against the official release.
5
6pkgname=binance-app
7pkgver=2.2.1
8pkgrel=1
9pkgdesc="Official Binance desktop application"
10arch=('x86_64')
11url="https://www.binance.com"
12license=('custom')
13depends=('gtk3' 'nss' 'alsa-lib' 'libxtst')
14source=("binance-${pkgver}.deb::https://ftp.binance.com/electron-desktop/linux/production/binance-amd64-linux.deb")
15sha256sums=('25cf4c8b76a56cbf879479bf2844e674078dea9cca3f0c72789f8c18bcb59a08')
16
17package() {
18 cd "${srcdir}"
19 bsdtar -xf data.tar.* -C "${pkgdir}"
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion