cwtch-ui-bin

maintainer baboon · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from git.openprivacy.ca, which is the official self-hosted Gitea instance for the Open Privacy Research Society (the legitimate upstream developers of Cwtch). This is not a random personal host — it is the canonical upstream release host for this project. However, the sha512sums_x86_64 is set to 'SKIP', meaning there is no integrity verification of the downloaded binary. A prebuilt binary with no checksum verification is a genuine supply-chain concern: if the upstream host were compromised or the URL were redirected, arbitrary code would be executed on the user's system with no detection. The binary is extracted and installed directly. The medium rating is appropriate not because of the host's legitimacy (it is the real upstream), but because of the missing checksum on an executed binary package.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:18 source_x86_64=("https://git.openprivacy.ca/cwtch.im/cwtch-ui/releases/download/v1.16.1/cwtch-${pkgver}_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from git.openprivacy.ca, which is the official self-hosted Gitea instance for the Open Privacy Research Society (the legitimate upstream developers of Cwtch). This is not a random personal host — it is the canonical upstream release host for this project. However, the sha512sums_x86_64 is set to 'SKIP', meaning there is no integrity verification of the downloaded binary. A prebuilt binary with no checksum verification is a genuine supply-chain concern: if the upstream host were compromised or the URL were redirected, arbitrary code would be executed on the user's system with no detection. The binary is extracted and installed directly. The medium rating is appropriate not because of the host's legitimacy (it is the real upstream), but because of the missing checksum on an executed binary package.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: baboon
2
3pkgname=cwtch-ui-bin
4_pkgname=cwtch-ui
5pkgver=1.16.1
6pkgrel=1
7pkgdesc="A Flutter based Cwtch UI"
8provides=('cwtch' 'cwtch-ui')
9conflicts=('cwtch' 'cwtch-git' 'libcwtch-go' 'cwtch-bin')
10provides=('cwtch' 'cwtch-ui')
11arch=('x86_64')
12url='https://cwtch.im'
13license=('MIT')
14optdepends=(
15 'tor: use system tor'
16)
17
18source_x86_64=("https://git.openprivacy.ca/cwtch.im/cwtch-ui/releases/download/v1.16.1/cwtch-${pkgver}_amd64.deb")
19sha512sums_x86_64=('SKIP')
20options=('!strip')
21
22package() {
23 cd $pkgdir
24 tar xf $srcdir/data.tar.*
25}
26

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion