dike

maintainer marcosbox · 4 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary tarball from rinnovofirma.infocert.it/download/x86_64/latest — a URL with no version in the path (just 'latest'), meaning the file can be silently replaced at any time by whoever controls that host. InfoCert S.p.A. is a legitimate Italian CA/digital-signature vendor, so this is not a random personal host, but the 'latest' URL pattern means the sha256sum pinned in the PKGBUILD will become stale the moment InfoCert updates the binary, and any future build will fail checksum verification (or worse, if the maintainer updates the sum without review). The binary is extracted and installed directly into the system (tar -xvf data.tar.xz -C pkgdir), so whatever is in that tarball runs with full system access. The sha256sum does provide a point-in-time integrity check, but the opaque 'latest' URL with no version string makes ongoing supply-chain auditability poor. This is a real medium-severity concern: an executed prebuilt binary from a vendor-controlled but non-auditable rolling URL, mitigated only by the current checksum pin.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=('https://www.firma.infocert.it/pdf/licenza-dike6.pdf'
  • PKGBUILD:14 'https://rinnovofirma.infocert.it/download/x86_64/latest')
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary tarball from rinnovofirma.infocert.it/download/x86_64/latest — a URL with no version in the path (just 'latest'), meaning the file can be silently replaced at any time by whoever controls that host. InfoCert S.p.A. is a legitimate Italian CA/digital-signature vendor, so this is not a random personal host, but the 'latest' URL pattern means the sha256sum pinned in the PKGBUILD will become stale the moment InfoCert updates the binary, and any future build will fail checksum verification (or worse, if the maintainer updates the sum without review). The binary is extracted and installed directly into the system (tar -xvf data.tar.xz -C pkgdir), so whatever is in that tarball runs with full system access. The sha256sum does provide a point-in-time integrity check, but the opaque 'latest' URL with no version string makes ongoing supply-chain auditability poor. This is a real medium-severity concern: an executed prebuilt binary from a vendor-controlled but non-auditable rolling URL, mitigated only by the current checksum pin.

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: Marco Giannini
2# Contributor:
3pkgname=dike
4pkgver=20210507
5pkgrel=1
6pkgdesc="Tool di firma e rinnovo online per i certificati digitali emessi da InfoCert S.p.A."
7arch=('x86_64')
8url="https://www.infocert.it"
9license=('custom:EULA')
10groups=()
11install=$pkgname.install
12depends=('libnotify' 'usb_modeswitch' 'pcsclite' 'pcsc-tools' 'gstreamer' 'libcanberra' 'libxinerama' 'libappindicator-gtk2')
13source=('https://www.firma.infocert.it/pdf/licenza-dike6.pdf'
14 'https://rinnovofirma.infocert.it/download/x86_64/latest')
15sha256sums=('d230fdf28a788fdbea6e9d7f2c7ab48f41c6f218419b8737ee06b34cb477644c'
16 '1beb0c04ac5cb4506eca09a17bb757b3b45dc3497e0d9c53c9bd8fb6f409b941')
17
18package() {
19 cd ${srcdir}
20 # extracting binaries
21 tar -xvf data.tar.xz -C ${pkgdir}
22 # installing license
23 install -m 755 -d "${pkgdir}/usr/share/licenses/${pkgname}"
24 install -m 644 -t "${pkgdir}/usr/share/licenses/${pkgname}" "${srcdir}/licenza-dike6.pdf"
25}
26

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion