ediary-bin
Installs a prebuilt proprietary binary (.deb) downloaded from a personal/project host (down.haoxg.net) that is not official infrastructure and could be silently swapped; checksums are present which mitigates but does not eliminate the risk of an unverifiable closed-source executable from a non-whitelisted host.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:29
"${_deb}::https://down.haoxg.net/download/ediary/linux/ediary_${_debver}_amd64.deb" -
PKGBUILD:31
source=('ediary-terms.html::https://www.haoxg.net/terms-of-service.php')
llm_review
An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): Installs a prebuilt proprietary binary (.deb) downloaded from a personal/project host (down.haoxg.net) that is not official infrastructure and could be silently swapped; checksums are present which mitigates but does not eliminate the risk of an unverifiable closed-source executable from a non-whitelisted host.
PKGBUILD
2 offending line(s) highlighted# Maintainer: czyt <czytcn@gmail.com>
pkgname=ediary-bin
pkgver=1.0.beta2
pkgrel=2
pkgdesc="A free, time-based diary and personal document manager"
arch=('x86_64')
url="https://www.haoxg.net"
license=('LicenseRef-Proprietary')
depends=(
'cairo'
'gcc-libs'
'gdk-pixbuf2'
'glibc'
'gtk3'
'libx11'
'pango'
'zlib'
)
makedepends=('libarchive')
provides=("ediary=${pkgver}")
conflicts=('ediary')
options=('!debug' '!strip')
_debver='1.0~beta2-2'
_deb="ediary_${_debver}_amd64.deb"
source_x86_64=(
"${_deb}::https://down.haoxg.net/download/ediary/linux/ediary_${_debver}_amd64.deb"
)
source=('ediary-terms.html::https://www.haoxg.net/terms-of-service.php')
noextract=("${_deb}")
sha256sums=('12f5b1c35eedcfc192b6e4a059955946b8635dcabd67e024bd9b0c27edd6b2d1')
sha256sums_x86_64=('4afebc465db89d43629ad4470988493ccc818d1239e96eb317a6b5f04028e80c')
package() {
local data_member
data_member=$(
bsdtar -tf "${srcdir}/${_deb}" |
awk '/^data[.]tar[.]/ { print; count++ } END { if (count != 1) exit 1 }'
) || {
printf 'Expected exactly one deb data archive in %s\n' "${_deb}" >&2
return 1
}
bsdtar -xOf "${srcdir}/${_deb}" "${data_member}" |
bsdtar --no-same-owner -xf - -C "${pkgdir}"
install -dm755 "${pkgdir}/usr/bin"
ln -s /opt/ediary/ediary "${pkgdir}/usr/bin/ediary"
install -Dm644 "${srcdir}/ediary-terms.html" \
"${pkgdir}/usr/share/licenses/${pkgname}/terms-of-service.html"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Medium | 2 |
| 2026-10-01 00:02:06 | Medium | 2 |
| 2026-09-30 00:20:07 | Medium | 2 |
| 2026-09-29 00:07:46 | Medium | 2 |
| 2026-09-28 00:28:32 | Medium | 2 |
| 2026-09-27 00:07:07 | Medium | 2 |
| 2026-09-26 00:12:15 | Medium | 2 |
| 2026-09-25 00:03:36 | Medium | 2 |
| 2026-09-24 00:24:14 | Medium | 2 |
| 2026-09-23 00:28:13 | Medium | 2 |
| 2026-09-22 00:15:14 | Medium | 2 |
| 2026-09-21 00:26:32 | Medium | 2 |
| 2026-09-20 00:25:31 | Medium | 2 |
| 2026-09-19 00:25:36 | Medium | 2 |
| 2026-09-18 00:17:11 | Medium | 2 |
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |