flexibee-client

MEDIUM
maintainer jirian 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The PKGBUILD downloads a prebuilt .deb binary (containing executable code/scripts) from download.flexibee.eu, which is the official vendor download host for the ABRA FlexiBee accounting software. The host itself is legitimate and vendor-controlled, so this is not an unofficial or personal host. However, sha256sums='SKIP' means there is no integrity verification of the downloaded binary, creating a real supply-chain risk: if the download is intercepted (MITM — note the source URL uses HTTP, not HTTPS... actually it does use HTTPS), or if the vendor host is compromised, a malicious binary could be installed without detection. The URL does use HTTPS which mitigates MITM somewhat, but the complete absence of a checksum for an executed binary is a genuine medium-severity concern. The package extracts and installs binaries from the .deb directly. This is a real but not clearly malicious supply-chain concern — the vendor host is legitimate but the missing checksum for executable content warrants medium severity.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("https://download.flexibee.eu/download/2025.7/${pkgver}/flexibee-client_${pkgver}_all.deb")
Medium AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt .deb binary (containing executable code/scripts) from download.flexibee.eu, which is the official vendor download host for the ABRA FlexiBee accounting software. The host itself is legitimate and vendor-controlled, so this is not an unofficial or personal host. However, sha256sums='SKIP' means there is no integrity verification of the downloaded binary, creating a real supply-chain risk: if the download is intercepted (MITM — note the source URL uses HTTP, not HTTPS... actually it does use HTTPS), or if the vendor host is compromised, a malicious binary could be installed without detection. The URL does use HTTPS which mitigates MITM somewhat, but the complete absence of a checksum for an executed binary is a genuine medium-severity concern. The package extracts and installs binaries from the .deb directly. This is a real but not clearly malicious supply-chain concern — the vendor host is legitimate but the missing checksum for executable content warrants medium severity.

PKGBUILD

1 offending line(s) highlighted
1# Maintainers: Jiri Antonu <jirka@nullable.group>, Matouš Kavalík <matous@kavalik.net>
2
3pkgname=flexibee-client-latest
4pkgver=2025.7.7
5pkgrel=1
6pkgdesc="ABRA Flexi Economic System (requires jdk11-temurin from AUR)"
7arch=('any')
8url="http://www.flexibee.eu/"
9license=('custom')
10depends=('xdg-utils')
11checkdepends=('jdk11-temurin')
12conflicts=('flexibee' 'flexibee-client' 'flexibee-client-bin')
13source=("https://download.flexibee.eu/download/2025.7/${pkgver}/flexibee-client_${pkgver}_all.deb")
14sha256sums=('SKIP')
15
16prepare() {
17 if [ ! -x /usr/lib/jvm/java-11-temurin/bin/java ]; then
18 echo "ABRA Flexi requires jdk11-temurin. Please install it from AUR."
19 exit 1
20 fi
21
22 # Extract the .deb package
23 ar x "flexibee-client_${pkgver}_all.deb" data.tar.* control.tar.* || true
24 tar -xf data.tar.* -C "$srcdir"
25}
26
27package() {
28 # Ensure target directories exist
29 mkdir -p "$pkgdir/usr/bin"
30 mkdir -p "$pkgdir/usr/share"
31
32 # Copy upstream files
33 cp -a usr/bin/* "$pkgdir/usr/bin/"
34 cp -a usr/share/* "$pkgdir/usr/share/"
35
36 # Configuration
37 install -Dm644 etc/default/flexibee "$pkgdir/etc/default/flexibee"
38}
39
40

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2
2026-09-12 00:25:17 Medium 2
2026-09-11 00:19:22 Medium 2
2026-09-10 00:22:44 Medium 2
2026-09-09 00:04:09 Medium 2
2026-09-08 00:18:08 Medium 2
2026-09-07 00:30:15 Medium 2
2026-09-06 00:17:06 Medium 2
2026-09-05 00:16:27 Medium 2
2026-09-04 00:03:13 Medium 2
2026-09-03 00:15:47 Medium 2
2026-09-02 00:02:31 Medium 2
2026-09-01 00:11:19 Medium 2
2026-08-31 00:19:57 Medium 2
2026-08-30 00:04:14 Medium 2
2026-08-29 00:29:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion