flexibee-client

maintainer jirian · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt .deb binary (containing executable code/scripts) from download.flexibee.eu, which is the official vendor download host for the ABRA FlexiBee accounting software. The host itself is legitimate and vendor-controlled, so this is not an unofficial or personal host. However, sha256sums='SKIP' means there is no integrity verification of the downloaded binary, creating a real supply-chain risk: if the download is intercepted (MITM — note the source URL uses HTTP, not HTTPS... actually it does use HTTPS), or if the vendor host is compromised, a malicious binary could be installed without detection. The URL does use HTTPS which mitigates MITM somewhat, but the complete absence of a checksum for an executed binary is a genuine medium-severity concern. The package extracts and installs binaries from the .deb directly. This is a real but not clearly malicious supply-chain concern — the vendor host is legitimate but the missing checksum for executable content warrants medium severity.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("https://download.flexibee.eu/download/2025.7/${pkgver}/flexibee-client_${pkgver}_all.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt .deb binary (containing executable code/scripts) from download.flexibee.eu, which is the official vendor download host for the ABRA FlexiBee accounting software. The host itself is legitimate and vendor-controlled, so this is not an unofficial or personal host. However, sha256sums='SKIP' means there is no integrity verification of the downloaded binary, creating a real supply-chain risk: if the download is intercepted (MITM — note the source URL uses HTTP, not HTTPS... actually it does use HTTPS), or if the vendor host is compromised, a malicious binary could be installed without detection. The URL does use HTTPS which mitigates MITM somewhat, but the complete absence of a checksum for an executed binary is a genuine medium-severity concern. The package extracts and installs binaries from the .deb directly. This is a real but not clearly malicious supply-chain concern — the vendor host is legitimate but the missing checksum for executable content warrants medium severity.

PKGBUILD

1 offending line(s) highlighted
1# Maintainers: Jiri Antonu <jirka@nullable.group>, Matouš Kavalík <matous@kavalik.net>
2
3pkgname=flexibee-client-latest
4pkgver=2025.7.7
5pkgrel=1
6pkgdesc="ABRA Flexi Economic System (requires jdk11-temurin from AUR)"
7arch=('any')
8url="http://www.flexibee.eu/"
9license=('custom')
10depends=('xdg-utils')
11checkdepends=('jdk11-temurin')
12conflicts=('flexibee' 'flexibee-client' 'flexibee-client-bin')
13source=("https://download.flexibee.eu/download/2025.7/${pkgver}/flexibee-client_${pkgver}_all.deb")
14sha256sums=('SKIP')
15
16prepare() {
17 if [ ! -x /usr/lib/jvm/java-11-temurin/bin/java ]; then
18 echo "ABRA Flexi requires jdk11-temurin. Please install it from AUR."
19 exit 1
20 fi
21
22 # Extract the .deb package
23 ar x "flexibee-client_${pkgver}_all.deb" data.tar.* control.tar.* || true
24 tar -xf data.tar.* -C "$srcdir"
25}
26
27package() {
28 # Ensure target directories exist
29 mkdir -p "$pkgdir/usr/bin"
30 mkdir -p "$pkgdir/usr/share"
31
32 # Copy upstream files
33 cp -a usr/bin/* "$pkgdir/usr/bin/"
34 cp -a usr/share/* "$pkgdir/usr/share/"
35
36 # Configuration
37 install -Dm644 etc/default/flexibee "$pkgdir/etc/default/flexibee"
38}
39
40

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion