cinc
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("http://downloads.cinc.sh/files/stable/cinc/${pkgver}/ubuntu/20.04/cinc_${pkgver}-1_amd64.deb")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from downloads.cinc.sh, which is the official Cinc Project distribution host (Cinc is the open-source, community-maintained fork of Chef). The host is not a random personal server — it is the project's official download infrastructure. However, the package installs a large, precompiled binary bundle (the full Cinc/Chef omnibus package) into /opt/cinc and links executables into /usr/bin. This is a real supply-chain concern: if downloads.cinc.sh were compromised, arbitrary code would be executed on the target system. The sha256sum provides integrity verification against the declared hash, but there is no GPG signature verification. The source is not a personal or unofficial host in the malicious sense, but it is not a standard distribution mirror either, and the payload is fully executed native code. This fits the medium category: a legitimate project's official binary host, but with the inherent risk of a large prebuilt binary blob without cryptographic signature verification beyond a single checksum.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Simon Vikstrom <aur@devsn.se>
pkgname=cinc
pkgver=16.12.3
pkgrel=1
_ubuntuver=xenial
pkgdesc="The Cinc installation package includes everything you need to start converging your machines."
arch=('x86_64')
url="https://cinc.sh/download/"
license=('Apache')
depends=()
conflicts=(chef chef-solo chef-dk chef-client)
source=("http://downloads.cinc.sh/files/stable/cinc/${pkgver}/ubuntu/20.04/cinc_${pkgver}-1_amd64.deb")
sha256sums=('81ea1b23068fb1c7069d53b9a9e2eb2497088d156caedba9147f940b7d33cd94')
package() {
cd "$srcdir"
bsdtar -xf data.tar.xz -C "$pkgdir"
# link executables
binaries="cinc-apply cinc-shell knife cinc-client cinc-solo ohai"
mkdir -p $pkgdir/usr/bin
for binary in $binaries; do
ln -s /opt/cinc/bin/$binary $pkgdir/usr/bin/ || error_exit "Cannot link $binary to /usr/bin"
done
chown -Rh 0:0 $pkgdir
chmod 755 $pkgdir/opt
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |