cohesivemail

maintainer actuallyreliable · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads a prebuilt binary tarball from 'dl.actuallyreliable.com', which is not a well-known or official software distribution host. The package installs a native executable (cohesivemail) directly to /opt and symlinks it to /usr/bin, meaning whatever is in that tarball runs with user privileges. The sha256sum provides integrity against accidental corruption but not against a compromised or malicious host serving a backdoored binary from the start. 'actuallyreliable.com' is an obscure, non-standard host with no established reputation as a software vendor CDN. There is no source code, no build step, and no way to audit what the binary does. This is a classic supply-chain risk pattern: prebuilt closed binary from an unofficial personal/unknown host. The cheaper model's MEDIUM rating is correct.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:39 "https://dl.actuallyreliable.com/apps/cohesivemail-x86-v${pkgver}.tar.gz"
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads a prebuilt binary tarball from 'dl.actuallyreliable.com', which is not a well-known or official software distribution host. The package installs a native executable (cohesivemail) directly to /opt and symlinks it to /usr/bin, meaning whatever is in that tarball runs with user privileges. The sha256sum provides integrity against accidental corruption but not against a compromised or malicious host serving a backdoored binary from the start. 'actuallyreliable.com' is an obscure, non-standard host with no established reputation as a software vendor CDN. There is no source code, no build step, and no way to audit what the binary does. This is a classic supply-chain risk pattern: prebuilt closed binary from an unofficial personal/unknown host. The cheaper model's MEDIUM rating is correct.

PKGBUILD

1 offending line(s) highlighted
1pkgname=cohesivemail
2pkgver=0.0.74
3pkgrel=2
4pkgdesc="CohesiveMail desktop client"
5arch=("x86_64")
6url="https://dl.actuallyreliable.com/apps"
7license=("custom")
8depends=(
9 "gtk3"
10 "glib2"
11 "pango"
12 "cairo"
13 "gdk-pixbuf2"
14 "harfbuzz"
15 "freetype2"
16 "fontconfig"
17 "libx11"
18 "libxext"
19 "libxrandr"
20 "libxrender"
21 "libxi"
22 "libxfixes"
23 "libxdamage"
24 "libxcomposite"
25 "libxcursor"
26 "libxkbcommon"
27 "wayland"
28 "libepoxy"
29 "mesa"
30 "dbus"
31 "at-spi2-core"
32 "wpewebkit"
33 "gstreamer"
34 "gst-plugins-base"
35)
36provides=("cohesivemail")
37conflicts=("cohesivemail")
38source=(
39 "https://dl.actuallyreliable.com/apps/cohesivemail-x86-v${pkgver}.tar.gz"
40 "cohesivemail.desktop"
41)
42sha256sums=(
43 "e3922f30683f5c7b7d68618f05b45464417a13807a2e4c6f2a1310a3a4a3d180"
44 "1f2deedd7276ffc37f4923c54c39261c8da7babbeb31e4be719c40b65238c6ad"
45)
46
47package() {
48 install -d "$pkgdir/opt/cohesivemail"
49 local src_root=("$srcdir"/cohesivemail*)
50 if [[ -d "${src_root[0]}" ]]; then
51 cp -a "${src_root[0]}/." "$pkgdir/opt/cohesivemail/"
52 else
53 cp -a "$srcdir"/* "$pkgdir/opt/cohesivemail/"
54 fi
55 chmod +x "$pkgdir/opt/cohesivemail/cohesivemail"
56
57 install -d "$pkgdir/usr/bin"
58 ln -s /opt/cohesivemail/cohesivemail "$pkgdir/usr/bin/cohesivemail"
59
60 install -Dm644 "$srcdir/cohesivemail.desktop" "$pkgdir/usr/share/applications/cohesivemail.desktop"
61}
62

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion