flexoptix

maintainer altf4arnold · 3 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The package downloads a prebuilt AppImage from a non-standard, potentially swappable host (flexbox.reconfigure.me), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("flexoptix-${pkgver}.AppImage::https://flexbox.reconfigure.me/download/electron/linux/x64/FLEXOPTIX%20App.${pkgver}-latest.AppImage"
  • PKGBUILD:14 'https://www.flexoptix.net/static/frontend/Flexoptix/default/en_US/files/99-tprogrammer.rules'
MEDIUM AI review llm_review

An AI model (qwen/qwen3-235b-a22b-07-25) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt AppImage from a non-standard, potentially swappable host (flexbox.reconfigure.me), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: Arnold DECHAMPS <ard at dechamps.aero>
2
3pkgname=flexoptix
4pkgver=5.65.1
5pkgrel=1
6pkgdesc='Flexoptix Flexbox transceiver programmer'
7arch=('any')
8url='https://www.flexoptix.net/en/flexoptix-app'
9license=('custom')
10depends=('hidapi')
11makedepends=('asar' 'nodejs')
12install=flexoptix.install
13source=("flexoptix-${pkgver}.AppImage::https://flexbox.reconfigure.me/download/electron/linux/x64/FLEXOPTIX%20App.${pkgver}-latest.AppImage"
14 'https://www.flexoptix.net/static/frontend/Flexoptix/default/en_US/files/99-tprogrammer.rules'
15 'disable-autoupdate.patch')
16sha256sums=('aafc501a93e00ba463eaf74fcc4d270711fb54335ef79b59cd84f866eb1d7624'
17 'ff566d253fb520cc98ab0dcdd1b549fd3def6e67b1d7af65cf1f92958e56b270'
18 'f1ae709af8a4c26d177d9339084b7dc73fd9bbb988f4e7601e0969f5f0121612')
19
20prepare() {
21 _appdir="${srcdir}/squashfs-root"
22
23 # extract appimage
24 chmod +x "${srcdir}/flexoptix-${pkgver}.AppImage"
25 "${srcdir}/flexoptix-${pkgver}.AppImage" --appimage-extract >/dev/null
26
27 # use system libs
28 rm -rf "${_appdir}/usr/lib"
29
30 # upstream updates cause the update checker to fail so
31 # we need to patch it out
32
33 asar extract "${_appdir}/resources/app.asar" app-asar
34 patch --forward -p0 --input="${srcdir}/disable-autoupdate.patch"
35 asar pack app-asar "${_appdir}/resources/app.asar"
36}
37
38package() {
39 _appdir="${srcdir}/squashfs-root"
40
41 install -d "${pkgdir}/opt/flexoptix"
42 install -d "${pkgdir}/usr/local/bin"
43
44 # install desktop entries
45 install -Dm644 "${_appdir}/flexoptix-app.desktop" "${pkgdir}/usr/share/applications/flexoptix-app.desktop"
46 install -Dm644 "${_appdir}/flexoptix-app.png" "${pkgdir}/usr/share/applications/flexoptix-app.png"
47 install -Dm644 "${_appdir}/usr/share/icons/hicolor/1024x1024/apps/flexoptix-app.png" "${pkgdir}/usr/share/icons/hicolor/0x0/apps/flexoptix-app.png"
48
49 # clean up unused bits
50 rm -rf "${_appdir}/usr" "${_appdir}/flexoptix-app.desktop" "{_appdir}/flexoptix-app.png"
51
52 # copy application
53 cp -rT "${_appdir}" "${pkgdir}/opt/flexoptix"
54 chmod -R 755 "${pkgdir}/opt/flexoptix"
55
56 # install USB udev rules
57 install -D "${srcdir}/99-tprogrammer.rules" "${pkgdir}/etc/udev/rules.d/99-flexoptix.rules"
58
59 ln -s "/opt/flexoptix/flexoptix-app" "${pkgdir}/usr/local/bin/flexoptix"
60}
61
62

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 3
2026-07-23 00:14:47 MEDIUM 3
2026-07-22 00:29:32 MEDIUM 3
2026-07-21 00:24:15 MEDIUM 3
2026-07-20 00:19:49 MEDIUM 3
2026-07-19 00:17:08 MEDIUM 3
2026-07-18 00:14:48 MEDIUM 3
2026-07-17 00:06:16 MEDIUM 3
2026-07-16 00:05:41 MEDIUM 3
2026-07-15 00:09:25 MEDIUM 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion