ctyun-clouddesk-bin

LOW
maintainer Ca11back 0 votes scanned 2026-10-06 08:09:03.243956
View on AUR
Why flagged

Downloads a proprietary .deb from desk.ctyun.cn (the vendor's own domain for China Telecom Cloud desktop client) with a pinned sha256 checksum; this is a standard binary repackaging of an official vendor release, not an unverifiable third-party host, so the risk is low despite the non-whitelisted host.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Downloads a proprietary .deb from desk.ctyun.cn (the vendor's own domain for China Telecom Cloud desktop client) with a pinned sha256 checksum; this is a standard binary repackaging of an official vendor release, not an unverifiable third-party host, so the risk is low despite the non-whitelisted host.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:26 source=("${pkgname}-${pkgver}.deb::https://desk.ctyun.cn/desktop/software/clientsoftware/download/7996be544023a0e2432281e1363f9fe2"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Ca11back
2# Contributor: venhal <1138706183@qq.com>
3
4pkgname=ctyun-clouddesk-bin
5pkgver=4.1.0.1346
6pkgrel=2
7pkgdesc="天翼云电脑 Linux 客户端(Public)"
8arch=('x86_64')
9url="https://www.ctyun.cn/products/cloudcomputer"
10license=('LicenseRef-Proprietary' '0BSD')
11options=('!strip' '!debug')
12provides=("ctyunclouddeskpublic-bin=$pkgver")
13conflicts=('ctyunclouddeskpublic-bin')
14
15depends=(
16 'alsa-lib' 'dbus' 'expat' 'fontconfig' 'freetype2' 'gdk-pixbuf2'
17 'glib2' 'glibc' 'gtk3' 'libdrm' 'libgcc' 'libglvnd' 'libgudev'
18 'libpulse' 'libstdc++' 'libx11' 'libxcb' 'libxcomposite' 'libxcursor'
19 'libxdamage' 'libxext' 'libxfixes' 'libxi' 'libxkbcommon'
20 'libxkbcommon-x11' 'libxrandr' 'libxrender' 'libxslt' 'libxss'
21 'nspr' 'nss' 'opus' 'pixman' 'sqlite' 'systemd-libs' 'v4l-utils'
22 'xcb-util-image' 'xcb-util-keysyms' 'xcb-util-renderutil' 'xcb-util-wm'
23 'xz' 'zlib'
24)
25
26source=("${pkgname}-${pkgver}.deb::https://desk.ctyun.cn/desktop/software/clientsoftware/download/7996be544023a0e2432281e1363f9fe2"
27 'ctyun-clouddesk' 'ctyunclouddeskpublic.conf' 'LICENSE')
28sha256sums=('61840ae48b70133844327c400da6f25fab1bf7f477225fccb319ff14df19f18a'
29 '3688a27a5fa9ab62304f65f4842164fd2a75b4b78b746c617f3ba21165234911'
30 '755c30a9b9fdd21a5ca1ce6eeee25b139e705af4acc88835bc1ffb1db292ca72'
31 '1d68fcad5c0989b4a28631cf48f32eeba6fddd88a277b4603a09f183eaea7d34')
32
33prepare() {
34 mkdir -p "$srcdir/payload"
35 bsdtar -xf "$srcdir/data.tar.gz" -C "$srcdir/payload"
36}
37
38package() {
39 cp -a "$srcdir/payload/opt" "$pkgdir/"
40 # Select desktop support rather than copying usr/bin's Debian updater.
41 install -Dm644 "$srcdir/payload/usr/share/applications/CtyunClouddeskPublic.desktop" \
42 "$pkgdir/usr/share/applications/CtyunClouddeskPublic.desktop"
43 # Debian /lib aliases /usr/lib on Arch; install units explicitly.
44 install -Dm644 "$srcdir/payload/lib/systemd/system/clouddesktop-daemon.service" \
45 "$pkgdir/usr/lib/systemd/system/clouddesktop-daemon.service"
46 install -Dm755 "$srcdir/ctyun-clouddesk" "$pkgdir/usr/bin/ctyun-clouddesk"
47 sed -i 's|^Exec=.*|Exec=/usr/bin/ctyun-clouddesk|' \
48 "$pkgdir/usr/share/applications/CtyunClouddeskPublic.desktop"
49 install -Dm644 "$srcdir/ctyunclouddeskpublic.conf" \
50 "$pkgdir/usr/lib/tmpfiles.d/ctyunclouddeskpublic.conf"
51 install -Dm644 "$srcdir/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/packaging-0BSD.txt"
52 # These are upstream third-party notices, not a license grant for the client.
53 cp -a "$srcdir/payload/opt/ctg/CtyunClouddeskPublic/licenses" \
54 "$pkgdir/usr/share/licenses/$pkgname/upstream"
55}
56

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 08:09:03 Low 3
2026-10-06 08:02:16 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion