forge-server-curios

maintainer orphaned · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged mediafiles.forgecdn.net is the official CurseForge CDN used by Overwolf/CurseForge to serve mod files — it is not a personal or unofficial host. The JAR is a Minecraft Forge mod (data/plugin for a game server), and its integrity is verified by a sha256sum. The file is installed into /srv/forge/mods/ as a mod asset, not executed as a system binary. The LICENSE is fetched from a GitHub blob URL (non-raw, which is slightly sloppy but not a security issue). Overall this is a standard mod-packaging pattern with checksum verification; the cheaper model's concern about the CDN host is a false positive.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): mediafiles.forgecdn.net is the official CurseForge CDN used by Overwolf/CurseForge to serve mod files — it is not a personal or unofficial host. The JAR is a Minecraft Forge mod (data/plugin for a game server), and its integrity is verified by a sha256sum. The file is installed into /srv/forge/mods/ as a mod asset, not executed as a system binary. The LICENSE is fetched from a GitHub blob URL (non-raw, which is slightly sloppy but not a security issue). Overall this is a standard mod-packaging pattern with checksum verification; the cheaper model's concern about the CDN host is a false positive.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 https://mediafiles.forgecdn.net/files/3871/347/curios-forge-1.19-5.1.0.4.jar)

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Dominik Opyd <d.opyd@oad.earth>
2
3pkgname=forge-server-curios
4modname=curios
5srvname=forge
6pkgver=5.1.0.4
7minver=1.19
8pkgrel=1
9
10url='https://www.curseforge.com/minecraft/mc-mods/curios'
11arch=('any')
12license=('GPL')
13pkgdesc="Curios is a flexible and expandable accessory/equipment API for users and developers."
14
15source=(https://github.com/TheIllusiveC4/Curios/blob/$minver.x/LICENSE
16 https://mediafiles.forgecdn.net/files/3871/347/curios-forge-1.19-5.1.0.4.jar)
17depends=("forge-server=41.1.0"
18 "forge-server-hooks=1.0.0")
19noextract=($modname-$srvname-$minver-$pkgver.jar)
20sha256sums=('ae651cfe7715ce791261be76c1b7d1e502c40502b7e2b7658bdac2d64157236b'
21 'ac80177420900486f6cca6e6a78d0aaa71fe18f86e951384ab24fb87fc3e4140')
22
23provides=(curios-forge)
24replaces=(curios-forge)
25conflicts=(curios-forge)
26
27package() {
28 install -Dm 2755 $srcdir/$modname-$srvname-$minver-$pkgver.jar $pkgdir/srv/$srvname/mods/$modname.jar
29
30 install -Dm 644 $srcdir/LICENSE ${pkgdir}/usr/share/licenses/${pkgname}/LICENSE
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion