cheatengine-bin

LOW
maintainer lapsus 4 votes scanned 2026-10-03 00:23:04.761738
View on AUR
Why flagged

The package downloads a prebuilt binary from the official project domain (cheatengine.org), which is not on standard whitelists but is plausibly legitimate; the build process installs only verified components from that archive without executing remote code or introducing untrusted dependencies.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a prebuilt binary from the official project domain (cheatengine.org), which is not on standard whitelists but is plausibly legitimate; the build process installs only verified components from that archive without executing remote code or introducing untrusted dependencies.

2 higher static findings superseded - not the current verdict (shown for transparency)
Medium External download from an untrusted host, not in source=() external_download_not_in_source

curl/wget fetches a URL on a non-allowlisted host that is not part of source=(), so it is not checksum-verified by makepkg.

  • PKGBUILD:129 curl -fsSL https://cheatengine.org/downloads.php |
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("CheatEngineLinux${pkgver/./}.zip::https://cheatengine.org/download/CheatEngineLinux${pkgver/./}.zip"

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: Yakov Till <yakov.till@gmail.com>
2pkgname=cheatengine-bin
3pkgver=7.7
4pkgrel=4
5pkgdesc="Memory scanner/debugger for game hacking and reverse engineering"
6arch=('x86_64')
7url="https://cheatengine.org"
8license=('LicenseRef-CheatEngine')
9depends=('qt6-base' 'libx11' 'glibc')
10makedepends=('python')
11provides=('cheatengine')
12conflicts=('cheatengine')
13options=('!strip' '!debug')
14source=("CheatEngineLinux${pkgver/./}.zip::https://cheatengine.org/download/CheatEngineLinux${pkgver/./}.zip"
15 "user-overlay.lua")
16sha256sums=('1e3c312061a270e67c67cf215cc1640027270bdea66fd2793dd156414992f6d4'
17 '7b0341d55bb5e16d473783eb7a5ab29552e3a91ab3f9a3f0aa9f79cebafe29c5')
18
19_instdir="usr/lib/cheatengine"
20
21package() {
22 install -dm755 "${pkgdir}/${_instdir}"
23
24 # Main binaries
25 install -Dm755 cheatengine-x86_64 "${pkgdir}/${_instdir}/cheatengine-x86_64"
26 install -Dm755 tutorial-x86_64 "${pkgdir}/${_instdir}/tutorial-x86_64"
27 install -Dm755 gtutorial-x86_64 "${pkgdir}/${_instdir}/gtutorial-x86_64"
28
29 # Bundled shared libraries (RUNPATH=$ORIGIN + dlopen from CWD)
30 for lib in libQt6Pas.so.6 liblua53.so libtcc-64.so libtcc-64-windows.so libtcc-32.so libtcc-32-windows.so libtcc-arm64.so \
31 libcrypt.so.1.1.0 libcrypto.so.1.1 libssl.so.1.1 \
32 libceapi.so libceserver-extension_x86_64_linux.so libceserver-extension_x86_linux.so libceserver-extension_i386_linux.so; do
33 install -Dm755 "$lib" "${pkgdir}/${_instdir}/$lib"
34 done
35
36 # Data files and scripts
37 for dir in autorun Extensions languages badassets lua include; do
38 cp -r --no-preserve=ownership "$dir" "${pkgdir}/${_instdir}/"
39 done
40
41 find "${pkgdir}/${_instdir}"/{autorun,Extensions,languages,badassets,lua,include} \
42 -type d -exec chmod 755 {} +
43 find "${pkgdir}/${_instdir}"/{autorun,Extensions,languages,badassets,lua,include} \
44 -type f -exec chmod 644 {} +
45 find "${pkgdir}/${_instdir}"/{autorun,Extensions,languages,badassets,lua,include} \
46 -type f -name '*.so' -exec chmod 755 {} +
47
48 # Config and data files
49 install -Dm644 main.lua "${pkgdir}/${_instdir}/main.lua"
50 install -Dm644 "${srcdir}/user-overlay.lua" "${pkgdir}/${_instdir}/user-overlay.lua"
51 install -Dm644 defines.lua "${pkgdir}/${_instdir}/defines.lua"
52 install -Dm644 celua.txt "${pkgdir}/${_instdir}/celua.txt"
53 install -Dm644 readme-linux.txt "${pkgdir}/${_instdir}/readme-linux.txt"
54
55 # License
56 install -Dm644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
57
58 # Launcher: CE resolves its content dir from /proc/self/exe (symlinks
59 # cannot relocate it) and dlopens some libs CWD-relative, so it runs from
60 # a per-user dir whose CWD-shadowed main.lua (user-overlay.lua) provides
61 # per-user autorun scripts on top of the read-only packaged tree.
62 install -Dm755 /dev/stdin "${pkgdir}/usr/bin/cheatengine" <<'EOF'
63#!/bin/sh
64pkgdir=/usr/lib/cheatengine
65userdir="${XDG_DATA_HOME:-$HOME/.local/share}/cheatengine"
66
67if mkdir -p "$userdir/autorun" 2>/dev/null; then
68 # .so symlinks for CWD-relative dlopen; never touch user-placed files/links
69 for lib in "$pkgdir"/*.so*; do
70 dest="$userdir/${lib##*/}"
71 [ ! -e "$dest" ] && [ ! -L "$dest" ] && ln -s "$lib" "$dest"
72 done
73 # drop our own symlinks left dangling by an upstream lib removal
74 for link in "$userdir"/*.so*; do
75 if [ -L "$link" ] && [ ! -e "$link" ]; then
76 case "$(readlink "$link")" in "$pkgdir"/*) rm -f "$link";; esac
77 fi
78 done
79 if [ ! -e "$userdir/main.lua" ] && [ ! -L "$userdir/main.lua" ]; then
80 ln -s "$pkgdir/user-overlay.lua" "$userdir/main.lua"
81 fi
82 if [ "$(readlink "$userdir/main.lua" 2>/dev/null)" = "$pkgdir/user-overlay.lua" ]; then
83 # our overlay main.lua re-runs the autorun scan with user precedence
84 cd "$userdir" && exec "$pkgdir/cheatengine-x86_64" NOAUTORUN "$@"
85 elif [ -f "$userdir/main.lua" ]; then
86 # user-authored main.lua: upstream shadow semantics, native autorun
87 cd "$userdir" && exec "$pkgdir/cheatengine-x86_64" "$@"
88 fi
89fi
90# unusable user dir: stock packaged behavior
91cd "$pkgdir" || exit 1
92exec ./cheatengine-x86_64 "$@"
93EOF
94
95 # Desktop entry
96 install -Dm644 /dev/stdin "${pkgdir}/usr/share/applications/cheatengine.desktop" <<'EOF'
97[Desktop Entry]
98Name=Cheat Engine
99Comment=Memory scanner/debugger for game hacking and reverse engineering
100Exec=cheatengine
101Icon=cheatengine
102StartupWMClass=cheatengine-x86_64
103Terminal=false
104Type=Application
105Categories=Development;Debugger;
106EOF
107
108 # Extract largest 128x128 PNG from binary (Lazarus-embedded app icon)
109 python3 -c "
110import struct
111with open('cheatengine-x86_64','rb') as f: d=f.read()
112m,p,best=b'\x89PNG\r\n\x1a\n',0,None
113while True:
114 p=d.find(m,p)
115 if p<0: break
116 e=d.find(b'IEND',p)
117 if e>0:
118 sz=e-p+8; c=d[p:p+sz]
119 w,h=struct.unpack('>II',c[16:24])
120 if w==128 and h==128 and (not best or sz>best[1]):
121 best=(p,sz)
122 p+=8
123open('icon.png','wb').write(d[best[0]:best[0]+best[1]])
124"
125 install -Dm644 icon.png "${pkgdir}/usr/share/pixmaps/cheatengine.png"
126}
127
128latestver() {
129 curl -fsSL https://cheatengine.org/downloads.php |
130 grep -aoP 'Download Cheat Engine \K[0-9]+(\.[0-9]+)+(?= For Linux)'
131}
132

Scan history

Scanned at (UTC)SeverityRules
2026-10-03 00:23:04 Low 3
2026-10-02 00:00:32 Low 3
2026-10-01 00:02:06 Low 3
2026-09-30 00:20:07 Low 3
2026-09-29 00:07:46 Low 3
2026-09-28 00:28:32 Low 3
2026-09-27 00:07:07 Low 3
2026-09-26 00:12:15 Low 3
2026-09-25 00:03:36 Low 3
2026-09-24 00:24:14 Low 3
2026-09-23 00:28:13 Low 3
2026-09-22 00:15:14 Low 3
2026-09-21 00:26:32 Low 3
2026-09-20 00:25:31 Low 3
2026-09-19 00:25:36 Low 3
2026-09-18 00:17:11 Low 3
2026-09-17 00:27:14 Low 3
2026-09-16 00:03:17 Low 3
2026-09-15 00:25:31 Low 3
2026-09-14 00:27:57 Low 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion