dsr

MEDIUM
maintainer Mylloon 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads a prebuilt binary from a non-standard, non-whitelisted host (git.mylloon.fr), which is not the project's official release infrastructure, posing a supply-chain risk if the host is compromised or malicious.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source_x86_64=("$pkgname-$pkgver.zip::https://git.mylloon.fr/Anri/dsr/releases/download/$pkgver/dsr-linux-x64-$pkgver.zip"
Medium AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 90%): The package downloads a prebuilt binary from a non-standard, non-whitelisted host (git.mylloon.fr), which is not the project's official release infrastructure, posing a supply-chain risk if the host is compromised or malicious.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Mylloon <aur@mylloon.fr>
2
3# shellcheck disable=SC2034,SC2148,SC2154
4
5pkgname='dsr'
6pkgver=2.4.1
7pkgrel=1
8pkgdesc="Video compression tool"
9arch=('x86_64')
10url=https://git.mylloon.fr/Anri/dsr
11license=('AGPL3')
12provides=("$pkgname")
13conflicts=("$pkgname")
14optdepends=('ffmpeg: needed for some encoders')
15source_x86_64=("$pkgname-$pkgver.zip::https://git.mylloon.fr/Anri/dsr/releases/download/$pkgver/dsr-linux-x64-$pkgver.zip"
16 "https://git.mylloon.fr/Anri/dsr/raw/branch/main/image/icon.png")
17sha256sums_x86_64=('8b5b6939b2af588988af990f092c11dcb9f81a45daa107e565cdc5219a5ddad0'
18 '4233e03f2fcfa583ccfe5358c8709b459f1f2e9048cad837bb93d69c92fba17f')
19
20package() {
21 # Install full app to /opt
22 install -d "$pkgdir/opt/$pkgname"
23 cp -r "$srcdir/dsr-linux-x64"/* "$pkgdir/opt/$pkgname"
24
25 # Symlink the binary to /usr/bin
26 install -d "$pkgdir/usr/bin"
27 ln -s "/opt/$pkgname/$pkgname" "$pkgdir/usr/bin/$pkgname"
28
29 install -Dm644 "$srcdir/icon.png" "$pkgdir/usr/share/pixmaps/$pkgname.png"
30
31 # Desktop entry
32 install -Dm644 /dev/stdin "$pkgdir/usr/share/applications/$pkgname.desktop" <<EOF
33[Desktop Entry]
34Type=Application
35Name=Video Compressor
36Comment=Compress video files
37Exec=/usr/bin/$pkgname %F
38Icon=$pkgname.png
39Terminal=false
40Categories=Utility;Video;
41MimeType=video/mp4;video/x-matroska;video/webm;
42EOF
43}
44

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2
2026-09-12 00:25:17 Medium 2
2026-09-11 00:19:22 Medium 2
2026-09-10 00:22:44 Medium 2
2026-09-09 00:04:09 Medium 2
2026-09-08 00:18:08 Medium 2
2026-09-07 00:30:15 Medium 2
2026-09-06 00:17:06 Medium 2
2026-09-05 00:16:27 Medium 2
2026-09-04 00:03:13 Medium 2
2026-09-03 00:15:47 Medium 2
2026-09-02 00:02:31 Medium 2
2026-09-01 00:11:19 Medium 2
2026-08-31 00:19:57 Medium 2
2026-08-30 00:04:14 Medium 2
2026-08-29 00:29:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion