flexoptix

MEDIUM
maintainer altf4arnold 3 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads a prebuilt AppImage from a non-standard, potentially swappable host (flexbox.reconfigure.me), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("flexoptix-${pkgver}.AppImage::https://flexbox.reconfigure.me/download/electron/linux/x64/FLEXOPTIX%20App.${pkgver}-latest.AppImage"
  • PKGBUILD:14 'https://www.flexoptix.net/static/frontend/Flexoptix/default/en_US/files/99-tprogrammer.rules'
Medium AI review llm_review

An AI model (qwen/qwen3-235b-a22b-07-25) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt AppImage from a non-standard, potentially swappable host (flexbox.reconfigure.me), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: Arnold DECHAMPS <ard at dechamps.aero>
2
3pkgname=flexoptix
4pkgver=5.65.1
5pkgrel=1
6pkgdesc='Flexoptix Flexbox transceiver programmer'
7arch=('any')
8url='https://www.flexoptix.net/en/flexoptix-app'
9license=('custom')
10depends=('hidapi')
11makedepends=('asar' 'nodejs')
12install=flexoptix.install
13source=("flexoptix-${pkgver}.AppImage::https://flexbox.reconfigure.me/download/electron/linux/x64/FLEXOPTIX%20App.${pkgver}-latest.AppImage"
14 'https://www.flexoptix.net/static/frontend/Flexoptix/default/en_US/files/99-tprogrammer.rules'
15 'disable-autoupdate.patch')
16sha256sums=('aafc501a93e00ba463eaf74fcc4d270711fb54335ef79b59cd84f866eb1d7624'
17 'ff566d253fb520cc98ab0dcdd1b549fd3def6e67b1d7af65cf1f92958e56b270'
18 'f1ae709af8a4c26d177d9339084b7dc73fd9bbb988f4e7601e0969f5f0121612')
19
20prepare() {
21 _appdir="${srcdir}/squashfs-root"
22
23 # extract appimage
24 chmod +x "${srcdir}/flexoptix-${pkgver}.AppImage"
25 "${srcdir}/flexoptix-${pkgver}.AppImage" --appimage-extract >/dev/null
26
27 # use system libs
28 rm -rf "${_appdir}/usr/lib"
29
30 # upstream updates cause the update checker to fail so
31 # we need to patch it out
32
33 asar extract "${_appdir}/resources/app.asar" app-asar
34 patch --forward -p0 --input="${srcdir}/disable-autoupdate.patch"
35 asar pack app-asar "${_appdir}/resources/app.asar"
36}
37
38package() {
39 _appdir="${srcdir}/squashfs-root"
40
41 install -d "${pkgdir}/opt/flexoptix"
42 install -d "${pkgdir}/usr/local/bin"
43
44 # install desktop entries
45 install -Dm644 "${_appdir}/flexoptix-app.desktop" "${pkgdir}/usr/share/applications/flexoptix-app.desktop"
46 install -Dm644 "${_appdir}/flexoptix-app.png" "${pkgdir}/usr/share/applications/flexoptix-app.png"
47 install -Dm644 "${_appdir}/usr/share/icons/hicolor/1024x1024/apps/flexoptix-app.png" "${pkgdir}/usr/share/icons/hicolor/0x0/apps/flexoptix-app.png"
48
49 # clean up unused bits
50 rm -rf "${_appdir}/usr" "${_appdir}/flexoptix-app.desktop" "{_appdir}/flexoptix-app.png"
51
52 # copy application
53 cp -rT "${_appdir}" "${pkgdir}/opt/flexoptix"
54 chmod -R 755 "${pkgdir}/opt/flexoptix"
55
56 # install USB udev rules
57 install -D "${srcdir}/99-tprogrammer.rules" "${pkgdir}/etc/udev/rules.d/99-flexoptix.rules"
58
59 ln -s "/opt/flexoptix/flexoptix-app" "${pkgdir}/usr/local/bin/flexoptix"
60}
61
62

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2
2026-09-12 00:25:17 Medium 2
2026-09-11 00:19:22 Medium 2
2026-09-10 00:22:44 Medium 2
2026-09-09 00:04:09 Medium 2
2026-09-08 00:18:08 Medium 2
2026-09-07 00:30:15 Medium 2
2026-09-06 00:17:06 Medium 2
2026-09-05 00:16:27 Medium 2
2026-09-04 00:03:13 Medium 2
2026-09-03 00:15:47 Medium 2
2026-09-02 00:02:31 Medium 2
2026-09-01 00:11:19 Medium 2
2026-08-31 00:19:57 Medium 2
2026-08-30 00:04:14 Medium 2
2026-08-29 00:29:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion