flexoptix
The package downloads a prebuilt AppImage from a non-standard, potentially swappable host (flexbox.reconfigure.me), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("flexoptix-${pkgver}.AppImage::https://flexbox.reconfigure.me/download/electron/linux/x64/FLEXOPTIX%20App.${pkgver}-latest.AppImage" -
PKGBUILD:14
'https://www.flexoptix.net/static/frontend/Flexoptix/default/en_US/files/99-tprogrammer.rules'
llm_review
An AI model (qwen/qwen3-235b-a22b-07-25) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt AppImage from a non-standard, potentially swappable host (flexbox.reconfigure.me), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.
PKGBUILD
2 offending line(s) highlighted# Maintainer: Arnold DECHAMPS <ard at dechamps.aero>
pkgname=flexoptix
pkgver=5.65.1
pkgrel=1
pkgdesc='Flexoptix Flexbox transceiver programmer'
arch=('any')
url='https://www.flexoptix.net/en/flexoptix-app'
license=('custom')
depends=('hidapi')
makedepends=('asar' 'nodejs')
install=flexoptix.install
source=("flexoptix-${pkgver}.AppImage::https://flexbox.reconfigure.me/download/electron/linux/x64/FLEXOPTIX%20App.${pkgver}-latest.AppImage"
'https://www.flexoptix.net/static/frontend/Flexoptix/default/en_US/files/99-tprogrammer.rules'
'disable-autoupdate.patch')
sha256sums=('aafc501a93e00ba463eaf74fcc4d270711fb54335ef79b59cd84f866eb1d7624'
'ff566d253fb520cc98ab0dcdd1b549fd3def6e67b1d7af65cf1f92958e56b270'
'f1ae709af8a4c26d177d9339084b7dc73fd9bbb988f4e7601e0969f5f0121612')
prepare() {
_appdir="${srcdir}/squashfs-root"
# extract appimage
chmod +x "${srcdir}/flexoptix-${pkgver}.AppImage"
"${srcdir}/flexoptix-${pkgver}.AppImage" --appimage-extract >/dev/null
# use system libs
rm -rf "${_appdir}/usr/lib"
# upstream updates cause the update checker to fail so
# we need to patch it out
asar extract "${_appdir}/resources/app.asar" app-asar
patch --forward -p0 --input="${srcdir}/disable-autoupdate.patch"
asar pack app-asar "${_appdir}/resources/app.asar"
}
package() {
_appdir="${srcdir}/squashfs-root"
install -d "${pkgdir}/opt/flexoptix"
install -d "${pkgdir}/usr/local/bin"
# install desktop entries
install -Dm644 "${_appdir}/flexoptix-app.desktop" "${pkgdir}/usr/share/applications/flexoptix-app.desktop"
install -Dm644 "${_appdir}/flexoptix-app.png" "${pkgdir}/usr/share/applications/flexoptix-app.png"
install -Dm644 "${_appdir}/usr/share/icons/hicolor/1024x1024/apps/flexoptix-app.png" "${pkgdir}/usr/share/icons/hicolor/0x0/apps/flexoptix-app.png"
# clean up unused bits
rm -rf "${_appdir}/usr" "${_appdir}/flexoptix-app.desktop" "{_appdir}/flexoptix-app.png"
# copy application
cp -rT "${_appdir}" "${pkgdir}/opt/flexoptix"
chmod -R 755 "${pkgdir}/opt/flexoptix"
# install USB udev rules
install -D "${srcdir}/99-tprogrammer.rules" "${pkgdir}/etc/udev/rules.d/99-flexoptix.rules"
ln -s "/opt/flexoptix/flexoptix-app" "${pkgdir}/usr/local/bin/flexoptix"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |