exam-env
The package downloads a prebuilt AppImage from a GitHub release URL, which is an unverifiable executable artifact; if the host were compromised or the release tampered with, it could deliver malicious code, though the source is from the project's official repository.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
https://raw.githubusercontent${_url#*github}/refs/heads/main/LICENSE.md
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 90%): The package downloads a prebuilt AppImage from a GitHub release URL, which is an unverifiable executable artifact; if the host were compromised or the release tampered with, it could deliver malicious code, though the source is from the project's official repository.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Ralph Torres <mail at ralphptorr dot es>
pkgname=exam-env
pkgver=2.2.0
pkgrel=1
pkgdesc='The freeCodeCamp Exam Environment desktop application'
arch=(x86_64)
url=https://freecodecamp.org
license=(BSD-3-Clause)
_pkgname=Exam.Environment
_pkgver=production
_url=https://github.com/freecodecamp/exam-env
source=(
$pkgname-$pkgver.AppImage::$_url/releases/download/$_pkgver/$pkgver/${_pkgname}_${pkgver}_amd64.AppImage
https://raw.githubusercontent${_url#*github}/refs/heads/main/LICENSE.md
)
sha256sums=(
293fbdd43a380200183b57d071e7e9e717f7a6e36c3bcd9d1651b06da966aa4a
b078ff602cbd37a85255691adf62a6ee232dbfba6105220827c1352002ad2941
)
options=(!debug !strip)
package() {
cd "$srcdir"
chmod +x $pkgname-$pkgver.AppImage
./$pkgname-$pkgver.AppImage --appimage-extract
# NOTE: tauri has issues in wayland envs, use temp workaround.
# should be fine since exam-env runs in x11 anyway
# refer: https://github.com/freeCodeCamp/exam-env/issues/107
# refer: https://github.com/tauri-apps/tauri/issues/8541
rm squashfs-root/usr/lib/*wayland*so*
install -Dm755 -d "$pkgdir"/opt/$pkgname
cp -r squashfs-root/* "$pkgdir"/opt/$pkgname/
chmod +rx "$pkgdir"/opt/$pkgbase/AppRun.wrapped
install -Dm755 /dev/stdin "$pkgdir"/usr/bin/$pkgname <<EOF
#!/bin/sh
exec /opt/$pkgname/AppRun "\$@"
EOF
install -Dm644 -t "$pkgdir"/usr/share/licenses/$pkgname LICENSE.md
cd squashfs-root
install -Dm644 -T Exam\ Environment.desktop \
"$pkgdir"/usr/share/applications/$pkgname.desktop
dir=usr/share/icons/hicolor
install -Dm644 -t "$pkgdir"/$dir/32x32/apps $dir/32x32/apps/$pkgname.png
install -Dm644 -t "$pkgdir"/$dir/128x128/apps $dir/128x128/apps/$pkgname.png
install -Dm644 -t "$pkgdir"/$dir/256x256@2/apps $dir/256x256@2/apps/$pkgname.png
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |