deluge-gtk-graceful-kill

maintainer Ayceman · 8 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The source is a prebuilt binary/archive fetched from Google Drive (a personal/unofficial host with no stable content guarantee). The file is installed directly into the package root via 'cp -a $srcdir/usr $pkgdir', meaning whatever is in that archive lands as executable files on the system. Google Drive links can be silently replaced by the owner, and the md5sum provides only weak integrity assurance (md5 is broken for collision resistance). The package installs a systemd service related to deluge shutdown, which runs with system privileges. This is a genuine supply-chain concern: executed/installed content from a non-reproducible personal host with weak checksum verification. Not clearly malicious, but the pattern matches a real medium-severity risk.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=('https://drive.google.com/uc?export=download&id=0Bwo48VGHJUUrVzBhSi0yMHR1UWc')
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The source is a prebuilt binary/archive fetched from Google Drive (a personal/unofficial host with no stable content guarantee). The file is installed directly into the package root via 'cp -a $srcdir/usr $pkgdir', meaning whatever is in that archive lands as executable files on the system. Google Drive links can be silently replaced by the owner, and the md5sum provides only weak integrity assurance (md5 is broken for collision resistance). The package installs a systemd service related to deluge shutdown, which runs with system privileges. This is a genuine supply-chain concern: executed/installed content from a non-reproducible personal host with weak checksum verification. Not clearly malicious, but the pattern matches a real medium-severity risk.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: alexandru.ianu@gmail.com
2
3
4pkgname=deluge-gtk-graceful-kill
5pkgver=d1.3_v15
6pkgrel=1
7pkgdesc="Systemd service to gracefully close deluge before shutdown/restart, avoiding a lock."
8arch=('i686' 'x86_64')
9url=https://forum.manjaro.org/index.php?topic=13035.0
10license=('GPL2')
11depends=('systemd' 'deluge')
12source=('https://drive.google.com/uc?export=download&id=0Bwo48VGHJUUrVzBhSi0yMHR1UWc')
13md5sums=('6e3de6d2257cac172ff3b685fc987d3b')
14
15install="$pkgname".install
16
17package() {
18 cp -a "$srcdir/usr" "$pkgdir"
19}
20

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion