decay-factory

maintainer Infinitybeond1 · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged Several real concerns here: (1) pip install during prepare() installs Python packages system-wide (or into the build environment) from PyPI based on an unpinned requirements.txt with no integrity verification (all sha256sums are 'SKIP'). This means any package listed in requirements.txt could be substituted or updated to a malicious version at any time. (2) All three source files are fetched from a mutable GitHub raw URL (main branch, not a tagged release or commit hash) with SKIP checksums, meaning the content can change at any time without detection. (3) pip install -r runs during the makepkg prepare() phase, which executes arbitrary code from PyPI packages. (4) The installed script conv.py is placed in /usr/bin and made executable, running arbitrary Python. The combination of mutable sources, no integrity checks, and pip executing third-party code during build constitutes a genuine supply-chain risk, confirming the MEDIUM rating.

Triggered rules

MEDIUM pip install of an external package pip_install_external

`pip install <package>` fetches an unpinned package from PyPI at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:18 pip3 install -r req.txt
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): Several real concerns here: (1) pip install during prepare() installs Python packages system-wide (or into the build environment) from PyPI based on an unpinned requirements.txt with no integrity verification (all sha256sums are 'SKIP'). This means any package listed in requirements.txt could be substituted or updated to a malicious version at any time. (2) All three source files are fetched from a mutable GitHub raw URL (main branch, not a tagged release or commit hash) with SKIP checksums, meaning the content can change at any time without detection. (3) pip install -r runs during the makepkg prepare() phase, which executes arbitrary code from PyPI packages. (4) The installed script conv.py is placed in /usr/bin and made executable, running arbitrary Python. The combination of mutable sources, no integrity checks, and pip executing third-party code during build constitutes a genuine supply-chain risk, confirming the MEDIUM rating.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Luke <Infinitybeond1@protonmail.com>
2
3pkgname='decay-factory'
4pkgdesc="A simple cli to convert any image to a Decay themed wallpaper"
5pkgver=1.0
6pkgrel=1
7arch=('x86_64')
8url="https://github.com/decaycs/decay-factory"
9license=('GPL3')
10source=("conv.py::https://raw.githubusercontent.com/decaycs/decay-factory/main/conv.py"
11 "decay.sh::https://raw.githubusercontent.com/decaycs/decay-factory/main/decay.sh"
12 "req.txt::https://raw.githubusercontent.com/decaycs/decay-factory/main/requirements.txt"
13 )
14makedepends=('python-pip')
15depends=('python3' 'bash')
16
17prepare() {
18 pip3 install -r req.txt
19}
20
21build() {
22 chmod 755 decay.sh
23 chmod 755 conv.py
24}
25
26package() {
27 install -D "conv.py" "$pkgdir/usr/bin/decayFactorypy"
28 install -D "decay.sh" "$pkgdir/usr/bin/decayFactory"
29}
30
31sha256sums=('SKIP' 'SKIP' 'SKIP')
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion