bshchk-bin

maintainer blek · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads prebuilt binaries from git.blek.codes, which is a self-hosted Gitea instance run by the maintainer rather than an official distribution channel. The binary is executed directly after installation. While PGP signature verification is present (validpgpkeys is set and .asc files are downloaded alongside the binaries), the sha256sums are all SKIP'd — meaning integrity is delegated entirely to PGP. The security posture depends on whether the PGP key A6C038E03D212D06575053ADA622C22C9BC616B2 is trustworthy and whether the self-hosted forge can be compromised. This is a classic medium-risk pattern: a prebuilt binary from a personal/unofficial host with no hash pinning, only PGP. Not clearly malicious, but a real supply-chain concern if the host or key is compromised.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 "https://git.blek.codes/blek/bshchk/releases/download/$pkgver/bshchk.linux.amd64"
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads prebuilt binaries from git.blek.codes, which is a self-hosted Gitea instance run by the maintainer rather than an official distribution channel. The binary is executed directly after installation. While PGP signature verification is present (validpgpkeys is set and .asc files are downloaded alongside the binaries), the sha256sums are all SKIP'd — meaning integrity is delegated entirely to PGP. The security posture depends on whether the PGP key A6C038E03D212D06575053ADA622C22C9BC616B2 is trustworthy and whether the self-hosted forge can be compromised. This is a classic medium-risk pattern: a prebuilt binary from a personal/unofficial host with no hash pinning, only PGP. Not clearly malicious, but a real supply-chain concern if the host or key is compromised.

PKGBUILD

1 offending line(s) highlighted
1pkgname=bshchk-bin
2pkgver=1.1
3pkgrel=1
4arch=('x86_64' 'aarch64')
5license=('GPL-3.0-only')
6provides=('bshchk')
7conflicts=('bshchk')
8
9source_x86_64=(
10 "https://git.blek.codes/blek/bshchk/releases/download/$pkgver/bshchk.linux.amd64"
11 "https://git.blek.codes/blek/bshchk/releases/download/$pkgver/bshchk.linux.amd64.asc"
12)
13source_aarch64=(
14 "https://git.blek.codes/blek/bshchk/releases/download/$pkgver/bshchk.linux.arm64"
15 "https://git.blek.codes/blek/bshchk/releases/download/$pkgver/bshchk.linux.arm64.asc"
16)
17
18validpgpkeys=('A6C038E03D212D06575053ADA622C22C9BC616B2')
19sha256sums_x86_64=('SKIP' 'SKIP')
20sha256sums_aarch64=('SKIP' 'SKIP')
21
22package() {
23 file=$(find . -name "bshchk.linux.*" | grep -vE '.asc$')
24 install -Dm755 $file "$pkgdir/usr/bin/bshchk"
25}
26

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion