flexibee-client
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("https://download.flexibee.eu/download/2025.7/${pkgver}/flexibee-client_${pkgver}_all.deb")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt .deb binary (containing executable code/scripts) from download.flexibee.eu, which is the official vendor download host for the ABRA FlexiBee accounting software. The host itself is legitimate and vendor-controlled, so this is not an unofficial or personal host. However, sha256sums='SKIP' means there is no integrity verification of the downloaded binary, creating a real supply-chain risk: if the download is intercepted (MITM — note the source URL uses HTTP, not HTTPS... actually it does use HTTPS), or if the vendor host is compromised, a malicious binary could be installed without detection. The URL does use HTTPS which mitigates MITM somewhat, but the complete absence of a checksum for an executed binary is a genuine medium-severity concern. The package extracts and installs binaries from the .deb directly. This is a real but not clearly malicious supply-chain concern — the vendor host is legitimate but the missing checksum for executable content warrants medium severity.
PKGBUILD
1 offending line(s) highlighted# Maintainers: Jiri Antonu <jirka@nullable.group>, Matouš Kavalík <matous@kavalik.net>
pkgname=flexibee-client-latest
pkgver=2025.7.7
pkgrel=1
pkgdesc="ABRA Flexi Economic System (requires jdk11-temurin from AUR)"
arch=('any')
url="http://www.flexibee.eu/"
license=('custom')
depends=('xdg-utils')
checkdepends=('jdk11-temurin')
conflicts=('flexibee' 'flexibee-client' 'flexibee-client-bin')
source=("https://download.flexibee.eu/download/2025.7/${pkgver}/flexibee-client_${pkgver}_all.deb")
sha256sums=('SKIP')
prepare() {
if [ ! -x /usr/lib/jvm/java-11-temurin/bin/java ]; then
echo "ABRA Flexi requires jdk11-temurin. Please install it from AUR."
exit 1
fi
# Extract the .deb package
ar x "flexibee-client_${pkgver}_all.deb" data.tar.* control.tar.* || true
tar -xf data.tar.* -C "$srcdir"
}
package() {
# Ensure target directories exist
mkdir -p "$pkgdir/usr/bin"
mkdir -p "$pkgdir/usr/share"
# Copy upstream files
cp -a usr/bin/* "$pkgdir/usr/bin/"
cp -a usr/share/* "$pkgdir/usr/share/"
# Configuration
install -Dm644 etc/default/flexibee "$pkgdir/etc/default/flexibee"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |