confirmo-bin

maintainer czyt · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from updates.confirmo.love, which is the vendor's own update/distribution host for the Confirmo desktop AI assistant application. While this is not a well-known major vendor, it is the official distribution channel for this specific proprietary application (consistent with the product URL confirmo.love). The binary is extracted and installed directly without any signature verification beyond a weak MD5 checksum. This is a classic AUR -bin package pattern for proprietary software distributed via the vendor's own CDN/update server. The concern is real but not elevated: the host appears to be the legitimate vendor update server, not a random personal host, but there is no GPG/SHA256 signature verification, and the MD5 checksum provides minimal integrity assurance. This is a genuine medium-severity supply-chain concern — a prebuilt executable from a non-mainstream host with only MD5 verification — but there is no evidence of active malice or substitution.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=("confirmo_${pkgver}_amd64.deb::https://updates.confirmo.love/confirmo_${pkgver}_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt binary .deb from updates.confirmo.love, which is the vendor's own update/distribution host for the Confirmo desktop AI assistant application. While this is not a well-known major vendor, it is the official distribution channel for this specific proprietary application (consistent with the product URL confirmo.love). The binary is extracted and installed directly without any signature verification beyond a weak MD5 checksum. This is a classic AUR -bin package pattern for proprietary software distributed via the vendor's own CDN/update server. The concern is real but not elevated: the host appears to be the legitimate vendor update server, not a random personal host, but there is no GPG/SHA256 signature verification, and the MD5 checksum provides minimal integrity assurance. This is a genuine medium-severity supply-chain concern — a prebuilt executable from a non-mainstream host with only MD5 verification — but there is no evidence of active malice or substitution.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: czyt <czytcn@gmail.com>
2pkgname=confirmo-bin
3pkgver=1.0.96
4pkgrel=1
5pkgdesc="Your AI coding companion that lives on your desktop"
6arch=('x86_64')
7url="https://confirmo.love"
8license=('MIT')
9depends=('gtk3' 'libnotify' 'nss' 'libxss' 'libxtst' 'xdg-utils' 'at-spi2-core' 'util-linux-libs' 'libsecret')
10optdepends=('libappindicator-gtk3: for system tray icon support')
11source=("confirmo_${pkgver}_amd64.deb::https://updates.confirmo.love/confirmo_${pkgver}_amd64.deb")
12md5sums=('15f86604f587fd09696a4fab041b58d9')
13
14package() {
15 # Extract the deb package
16 bsdtar -xOf "${srcdir}/confirmo_${pkgver}_amd64.deb" data.tar.xz | bsdtar -xC "${pkgdir}"
17
18 # Fix permissions
19 chmod -R u=rwX,go=rX "${pkgdir}"
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion