dike
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=('https://www.firma.infocert.it/pdf/licenza-dike6.pdf' -
PKGBUILD:14
'https://rinnovofirma.infocert.it/download/x86_64/latest')
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary tarball from rinnovofirma.infocert.it/download/x86_64/latest — a URL with no version in the path (just 'latest'), meaning the file can be silently replaced at any time by whoever controls that host. InfoCert S.p.A. is a legitimate Italian CA/digital-signature vendor, so this is not a random personal host, but the 'latest' URL pattern means the sha256sum pinned in the PKGBUILD will become stale the moment InfoCert updates the binary, and any future build will fail checksum verification (or worse, if the maintainer updates the sum without review). The binary is extracted and installed directly into the system (tar -xvf data.tar.xz -C pkgdir), so whatever is in that tarball runs with full system access. The sha256sum does provide a point-in-time integrity check, but the opaque 'latest' URL with no version string makes ongoing supply-chain auditability poor. This is a real medium-severity concern: an executed prebuilt binary from a vendor-controlled but non-auditable rolling URL, mitigated only by the current checksum pin.
PKGBUILD
2 offending line(s) highlighted# Maintainer: Marco Giannini
# Contributor:
pkgname=dike
pkgver=20210507
pkgrel=1
pkgdesc="Tool di firma e rinnovo online per i certificati digitali emessi da InfoCert S.p.A."
arch=('x86_64')
url="https://www.infocert.it"
license=('custom:EULA')
groups=()
install=$pkgname.install
depends=('libnotify' 'usb_modeswitch' 'pcsclite' 'pcsc-tools' 'gstreamer' 'libcanberra' 'libxinerama' 'libappindicator-gtk2')
source=('https://www.firma.infocert.it/pdf/licenza-dike6.pdf'
'https://rinnovofirma.infocert.it/download/x86_64/latest')
sha256sums=('d230fdf28a788fdbea6e9d7f2c7ab48f41c6f218419b8737ee06b34cb477644c'
'1beb0c04ac5cb4506eca09a17bb757b3b45dc3497e0d9c53c9bd8fb6f409b941')
package() {
cd ${srcdir}
# extracting binaries
tar -xvf data.tar.xz -C ${pkgdir}
# installing license
install -m 755 -d "${pkgdir}/usr/share/licenses/${pkgname}"
install -m 644 -t "${pkgdir}/usr/share/licenses/${pkgname}" "${srcdir}/licenza-dike6.pdf"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |