cohesivemail

MEDIUM
maintainer actuallyreliable 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

This PKGBUILD downloads a prebuilt binary tarball from 'dl.actuallyreliable.com', which is not a well-known or official software distribution host. The package installs a native executable (cohesivemail) directly to /opt and symlinks it to /usr/bin, meaning whatever is in that tarball runs with user privileges. The sha256sum provides integrity against accidental corruption but not against a compromised or malicious host serving a backdoored binary from the start. 'actuallyreliable.com' is an obscure, non-standard host with no established reputation as a software vendor CDN. There is no source code, no build step, and no way to audit what the binary does. This is a classic supply-chain risk pattern: prebuilt closed binary from an unofficial personal/unknown host. The cheaper model's MEDIUM rating is correct.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:39 "https://dl.actuallyreliable.com/apps/cohesivemail-x86-v${pkgver}.tar.gz"
Medium AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads a prebuilt binary tarball from 'dl.actuallyreliable.com', which is not a well-known or official software distribution host. The package installs a native executable (cohesivemail) directly to /opt and symlinks it to /usr/bin, meaning whatever is in that tarball runs with user privileges. The sha256sum provides integrity against accidental corruption but not against a compromised or malicious host serving a backdoored binary from the start. 'actuallyreliable.com' is an obscure, non-standard host with no established reputation as a software vendor CDN. There is no source code, no build step, and no way to audit what the binary does. This is a classic supply-chain risk pattern: prebuilt closed binary from an unofficial personal/unknown host. The cheaper model's MEDIUM rating is correct.

PKGBUILD

1 offending line(s) highlighted
1pkgname=cohesivemail
2pkgver=0.0.74
3pkgrel=2
4pkgdesc="CohesiveMail desktop client"
5arch=("x86_64")
6url="https://dl.actuallyreliable.com/apps"
7license=("custom")
8depends=(
9 "gtk3"
10 "glib2"
11 "pango"
12 "cairo"
13 "gdk-pixbuf2"
14 "harfbuzz"
15 "freetype2"
16 "fontconfig"
17 "libx11"
18 "libxext"
19 "libxrandr"
20 "libxrender"
21 "libxi"
22 "libxfixes"
23 "libxdamage"
24 "libxcomposite"
25 "libxcursor"
26 "libxkbcommon"
27 "wayland"
28 "libepoxy"
29 "mesa"
30 "dbus"
31 "at-spi2-core"
32 "wpewebkit"
33 "gstreamer"
34 "gst-plugins-base"
35)
36provides=("cohesivemail")
37conflicts=("cohesivemail")
38source=(
39 "https://dl.actuallyreliable.com/apps/cohesivemail-x86-v${pkgver}.tar.gz"
40 "cohesivemail.desktop"
41)
42sha256sums=(
43 "e3922f30683f5c7b7d68618f05b45464417a13807a2e4c6f2a1310a3a4a3d180"
44 "1f2deedd7276ffc37f4923c54c39261c8da7babbeb31e4be719c40b65238c6ad"
45)
46
47package() {
48 install -d "$pkgdir/opt/cohesivemail"
49 local src_root=("$srcdir"/cohesivemail*)
50 if [[ -d "${src_root[0]}" ]]; then
51 cp -a "${src_root[0]}/." "$pkgdir/opt/cohesivemail/"
52 else
53 cp -a "$srcdir"/* "$pkgdir/opt/cohesivemail/"
54 fi
55 chmod +x "$pkgdir/opt/cohesivemail/cohesivemail"
56
57 install -d "$pkgdir/usr/bin"
58 ln -s /opt/cohesivemail/cohesivemail "$pkgdir/usr/bin/cohesivemail"
59
60 install -Dm644 "$srcdir/cohesivemail.desktop" "$pkgdir/usr/share/applications/cohesivemail.desktop"
61}
62

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2
2026-09-12 00:25:17 Medium 2
2026-09-11 00:19:22 Medium 2
2026-09-10 00:22:44 Medium 2
2026-09-09 00:04:09 Medium 2
2026-09-08 00:18:08 Medium 2
2026-09-07 00:30:15 Medium 2
2026-09-06 00:17:06 Medium 2
2026-09-05 00:16:27 Medium 2
2026-09-04 00:03:13 Medium 2
2026-09-03 00:15:47 Medium 2
2026-09-02 00:02:31 Medium 2
2026-09-01 00:11:19 Medium 2
2026-08-31 00:19:57 Medium 2
2026-08-30 00:04:14 Medium 2
2026-08-29 00:29:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion