citybound-bin

maintainer Phaotee · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary from an S3 bucket (citybound-livebuilds.s3.amazonaws.com) that is described as 'livebuilds' — i.e. a CI/CD artifact host rather than an official versioned release. The binary is executed directly and installed to /usr/bin. While the domain appears to belong to the upstream developer (aeplay.org/citybound), S3 buckets can be misconfigured, taken over, or have objects replaced without notice. There is no GPG signature verification, only an MD5 checksum (which provides integrity but not authenticity). The 'livebuilds' naming suggests these are rolling CI artifacts rather than pinned release tarballs, increasing the risk of silent replacement. This is a genuine medium-severity supply-chain concern: an executed binary from a non-standard/unofficial artifact host with no cryptographic authenticity guarantee.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("https://citybound-livebuilds.s3.amazonaws.com/citybound-v$pkgver-$pkgrel-$commit-linux.tar.gz")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary from an S3 bucket (citybound-livebuilds.s3.amazonaws.com) that is described as 'livebuilds' — i.e. a CI/CD artifact host rather than an official versioned release. The binary is executed directly and installed to /usr/bin. While the domain appears to belong to the upstream developer (aeplay.org/citybound), S3 buckets can be misconfigured, taken over, or have objects replaced without notice. There is no GPG signature verification, only an MD5 checksum (which provides integrity but not authenticity). The 'livebuilds' naming suggests these are rolling CI artifacts rather than pinned release tarballs, increasing the risk of silent replacement. This is a genuine medium-severity supply-chain concern: an executed binary from a non-standard/unofficial artifact host with no cryptographic authenticity guarantee.

PKGBUILD

1 offending line(s) highlighted
1# Mainintainer : Lucas Rooyakkers <lucas dot rooyakkers at pm dot me>
2pkgname=citybound-bin
3pkgver=0.1.2
4pkgrel=823
5commit="gdfa71eb"
6license=('GPL3')
7pkgdesc="A city building game that uses microscopic models to vividly simulate the organism of a city arising from the interactions of millions of individuals."
8url="https://aeplay.org/citybound"
9arch=('x86_64')
10provides=('citybound')
11conflicts=()
12source=("https://citybound-livebuilds.s3.amazonaws.com/citybound-v$pkgver-$pkgrel-$commit-linux.tar.gz")
13md5sums=('b280d48e57ed1d92b1b15606bf159050')
14
15package() {
16 tar -xzvf "citybound-v$pkgver-$pkgrel-$commit-linux.tar.gz"
17 install -Dm755 "citybound-v$pkgver-$pkgrel-$commit" "$pkgdir/usr/bin/citybound"
18}
19

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion