fractal-forest

maintainer dexield · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary from a personal DDNS host (dexieldvpn.ddns.net) rather than from the official GitHub releases page listed in the url= field. DDNS hostnames are dynamic and can be reassigned; the host is not an official distribution channel. While a sha256sum is present, it only verifies integrity at the time of packaging — if the binary at that URL is silently replaced, future installs would fetch a different binary (the checksum would catch that, but only if the PKGBUILD is updated). More critically, the binary itself is not built from source and comes from an unofficial personal server rather than GitHub releases, making it impossible to verify the build provenance. This is a genuine supply-chain concern: an executed binary from an unofficial/personal host, matching the definition of medium severity.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=("fractal-forest-bin-$pkgver-x86_64.tar.gz::http://dexieldvpn.ddns.net/fractal-forest-bin-$pkgver-x86_64.tar.gz")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 85%): The PKGBUILD downloads a prebuilt binary from a personal DDNS host (dexieldvpn.ddns.net) rather than from the official GitHub releases page listed in the url= field. DDNS hostnames are dynamic and can be reassigned; the host is not an official distribution channel. While a sha256sum is present, it only verifies integrity at the time of packaging — if the binary at that URL is silently replaced, future installs would fetch a different binary (the checksum would catch that, but only if the PKGBUILD is updated). More critically, the binary itself is not built from source and comes from an unofficial personal server rather than GitHub releases, making it impossible to verify the build provenance. This is a genuine supply-chain concern: an executed binary from an unofficial/personal host, matching the definition of medium severity.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: dexield
2pkgname=fractal-forest
3pkgver=0.1.0
4pkgrel=1
5pkgdesc="Real-time 3D fractal forest visualization in terminal"
6arch=('x86_64')
7url="https://github.com/dexield/fractal-forest"
8license=('MIT')
9depends=('glibc')
10source=("fractal-forest-bin-$pkgver-x86_64.tar.gz::http://dexieldvpn.ddns.net/fractal-forest-bin-$pkgver-x86_64.tar.gz")
11sha256sums=('a6ab2bb166b1da40d3e44457635dfb44e9fb392b92c8535e1d5a2415815cb46b')
12
13package() {
14 cd "$srcdir"
15 install -Dm755 "fractal-forest" "$pkgdir/usr/bin/fractal-forest"
16}
17

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion