ediary-bin

MEDIUM
maintainer czyt 0 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

Installs a prebuilt proprietary binary (.deb) downloaded from a personal/project host (down.haoxg.net) that is not official infrastructure and could be silently swapped; checksums are present which mitigates but does not eliminate the risk of an unverifiable closed-source executable from a non-whitelisted host.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:29 "${_deb}::https://down.haoxg.net/download/ediary/linux/ediary_${_debver}_amd64.deb"
  • PKGBUILD:31 source=('ediary-terms.html::https://www.haoxg.net/terms-of-service.php')
Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): Installs a prebuilt proprietary binary (.deb) downloaded from a personal/project host (down.haoxg.net) that is not official infrastructure and could be silently swapped; checksums are present which mitigates but does not eliminate the risk of an unverifiable closed-source executable from a non-whitelisted host.

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: czyt <czytcn@gmail.com>
2
3pkgname=ediary-bin
4pkgver=1.0.beta2
5pkgrel=2
6pkgdesc="A free, time-based diary and personal document manager"
7arch=('x86_64')
8url="https://www.haoxg.net"
9license=('LicenseRef-Proprietary')
10
11depends=(
12 'cairo'
13 'gcc-libs'
14 'gdk-pixbuf2'
15 'glibc'
16 'gtk3'
17 'libx11'
18 'pango'
19 'zlib'
20)
21makedepends=('libarchive')
22provides=("ediary=${pkgver}")
23conflicts=('ediary')
24options=('!debug' '!strip')
25
26_debver='1.0~beta2-2'
27_deb="ediary_${_debver}_amd64.deb"
28source_x86_64=(
29 "${_deb}::https://down.haoxg.net/download/ediary/linux/ediary_${_debver}_amd64.deb"
30)
31source=('ediary-terms.html::https://www.haoxg.net/terms-of-service.php')
32noextract=("${_deb}")
33sha256sums=('12f5b1c35eedcfc192b6e4a059955946b8635dcabd67e024bd9b0c27edd6b2d1')
34sha256sums_x86_64=('4afebc465db89d43629ad4470988493ccc818d1239e96eb317a6b5f04028e80c')
35
36package() {
37 local data_member
38
39 data_member=$(
40 bsdtar -tf "${srcdir}/${_deb}" |
41 awk '/^data[.]tar[.]/ { print; count++ } END { if (count != 1) exit 1 }'
42 ) || {
43 printf 'Expected exactly one deb data archive in %s\n' "${_deb}" >&2
44 return 1
45 }
46
47 bsdtar -xOf "${srcdir}/${_deb}" "${data_member}" |
48 bsdtar --no-same-owner -xf - -C "${pkgdir}"
49
50 install -dm755 "${pkgdir}/usr/bin"
51 ln -s /opt/ediary/ediary "${pkgdir}/usr/bin/ediary"
52
53 install -Dm644 "${srcdir}/ediary-terms.html" \
54 "${pkgdir}/usr/share/licenses/${pkgname}/terms-of-service.html"
55}
56

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Medium 2
2026-10-01 00:02:06 Medium 2
2026-09-30 00:20:07 Medium 2
2026-09-29 00:07:46 Medium 2
2026-09-28 00:28:32 Medium 2
2026-09-27 00:07:07 Medium 2
2026-09-26 00:12:15 Medium 2
2026-09-25 00:03:36 Medium 2
2026-09-24 00:24:14 Medium 2
2026-09-23 00:28:13 Medium 2
2026-09-22 00:15:14 Medium 2
2026-09-21 00:26:32 Medium 2
2026-09-20 00:25:31 Medium 2
2026-09-19 00:25:36 Medium 2
2026-09-18 00:17:11 Medium 2
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion