cinc

maintainer orphaned · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from downloads.cinc.sh, which is the official Cinc Project distribution host (Cinc is the open-source, community-maintained fork of Chef). The host is not a random personal server — it is the project's official download infrastructure. However, the package installs a large, precompiled binary bundle (the full Cinc/Chef omnibus package) into /opt/cinc and links executables into /usr/bin. This is a real supply-chain concern: if downloads.cinc.sh were compromised, arbitrary code would be executed on the target system. The sha256sum provides integrity verification against the declared hash, but there is no GPG signature verification. The source is not a personal or unofficial host in the malicious sense, but it is not a standard distribution mirror either, and the payload is fully executed native code. This fits the medium category: a legitimate project's official binary host, but with the inherent risk of a large prebuilt binary blob without cryptographic signature verification beyond a single checksum.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("http://downloads.cinc.sh/files/stable/cinc/${pkgver}/ubuntu/20.04/cinc_${pkgver}-1_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from downloads.cinc.sh, which is the official Cinc Project distribution host (Cinc is the open-source, community-maintained fork of Chef). The host is not a random personal server — it is the project's official download infrastructure. However, the package installs a large, precompiled binary bundle (the full Cinc/Chef omnibus package) into /opt/cinc and links executables into /usr/bin. This is a real supply-chain concern: if downloads.cinc.sh were compromised, arbitrary code would be executed on the target system. The sha256sum provides integrity verification against the declared hash, but there is no GPG signature verification. The source is not a personal or unofficial host in the malicious sense, but it is not a standard distribution mirror either, and the payload is fully executed native code. This fits the medium category: a legitimate project's official binary host, but with the inherent risk of a large prebuilt binary blob without cryptographic signature verification beyond a single checksum.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Simon Vikstrom <aur@devsn.se>
2
3pkgname=cinc
4pkgver=16.12.3
5pkgrel=1
6_ubuntuver=xenial
7pkgdesc="The Cinc installation package includes everything you need to start converging your machines."
8arch=('x86_64')
9url="https://cinc.sh/download/"
10license=('Apache')
11depends=()
12conflicts=(chef chef-solo chef-dk chef-client)
13source=("http://downloads.cinc.sh/files/stable/cinc/${pkgver}/ubuntu/20.04/cinc_${pkgver}-1_amd64.deb")
14sha256sums=('81ea1b23068fb1c7069d53b9a9e2eb2497088d156caedba9147f940b7d33cd94')
15
16package() {
17 cd "$srcdir"
18 bsdtar -xf data.tar.xz -C "$pkgdir"
19
20 # link executables
21 binaries="cinc-apply cinc-shell knife cinc-client cinc-solo ohai"
22
23 mkdir -p $pkgdir/usr/bin
24
25 for binary in $binaries; do
26 ln -s /opt/cinc/bin/$binary $pkgdir/usr/bin/ || error_exit "Cannot link $binary to /usr/bin"
27 done
28 chown -Rh 0:0 $pkgdir
29 chmod 755 $pkgdir/opt
30}
31

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion