foobar2000-component-musical-spectrum-bin
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=('https://hydrogenaud.io/index.php?action=dlattach;topic=97404.0;attach=7189')
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The source is a prebuilt Windows DLL (foo_musical_spectrum.dll) downloaded from a forum attachment URL on hydrogenaud.io. While hydrogenaud.io is a well-known audio enthusiast community and the URL references a specific forum attachment ID, forum attachment URLs are not official vendor release channels and can be silently replaced or removed. The DLL is installed directly without any signature verification beyond an MD5 checksum (which provides integrity but not authenticity). However, the impact is somewhat limited: this is a foobar2000 component (Windows-only DLL) being installed into /usr/share/foobar2000/components, so it only executes within foobar2000's plugin sandbox on a Windows application running under Wine. The md5sum provides basic integrity checking. The concern is real but moderate: a forum attachment from a community site with only MD5 verification is a genuine supply-chain concern for an executed binary, justifying MEDIUM rather than clean or low.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Connor McFarlane <cm at semtex dot net>
pkgname=foobar2000-component-musical-spectrum-bin
pkgver=0.9.1
pkgrel=4
_fooname='foo_musical_spectrum'
pkgdesc='A spectrum analyser visulisation component for foobar2000'
arch=('any')
url='https://wiki.hydrogenaud.io/index.php?title=Foobar2000:Components/Musical_Spectrum_(foo_musical_spectrum)'
license=('unknown')
depends=('foobar2000>=1.0.0')
source=('https://hydrogenaud.io/index.php?action=dlattach;topic=97404.0;attach=7189')
md5sums=('5a7317c95ead1ac48d05cf5512337a95')
package() {
install -Dm644 -t "$pkgdir/usr/share/foobar2000/components/${_fooname}" "$srcdir/${_fooname}.dll"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |