freeter

maintainer morenoprobst · 5 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt AppImage binary directly from freeter.io (the official project domain) and installs it as an executable. The sha256sum is pinned, which mitigates substitution attacks to some degree. However, the source URL points to a generic path 'Freeter.AppImage' with no version in the filename, meaning the checksum could become stale or the file could be silently replaced at the same URL. AppImages are self-contained executable binaries that run without further audit. The domain appears to be the legitimate upstream vendor site, so this is not clearly malicious, but distributing a versioned package that fetches a versionless binary URL is a real supply-chain concern: if the upstream ever rotates the file at that URL, the sha256 check would catch it, but the pattern is fragile. This is a genuine medium-severity concern (executed binary from a non-versioned URL), not a false positive, though it is not an active attack.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source=("https://freeter.io/download/Freeter.AppImage")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt AppImage binary directly from freeter.io (the official project domain) and installs it as an executable. The sha256sum is pinned, which mitigates substitution attacks to some degree. However, the source URL points to a generic path 'Freeter.AppImage' with no version in the filename, meaning the checksum could become stale or the file could be silently replaced at the same URL. AppImages are self-contained executable binaries that run without further audit. The domain appears to be the legitimate upstream vendor site, so this is not clearly malicious, but distributing a versioned package that fetches a versionless binary URL is a real supply-chain concern: if the upstream ever rotates the file at that URL, the sha256 check would catch it, but the pattern is fragile. This is a genuine medium-severity concern (executed binary from a non-versioned URL), not a false positive, though it is not an active attack.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: David Birks <david@tellus.space>
2# Contributor: Aner Andros <code@anerandros.info>
3
4pkgname=freeter
5pkgver=1.2.1
6pkgrel=2
7pkgdesc="The smartest way to work on your projects"
8arch=("x86_64" "i686")
9url="https://freeter.io"
10license=("custom")
11depends=("glib2" "fuse2")
12optdepends=()
13provides=("freeter")
14options=(!strip)
15
16source=("https://freeter.io/download/Freeter.AppImage")
17
18sha256sums=("7e10416460abdeb55f81d6ae0650476ae19c76f10a20ca895ea53c8d81d4ddb9")
19
20noextract=("Freeter.AppImage")
21
22package() {
23 install -d "$pkgdir"/{opt/freeter,usr/bin}
24
25 install -m755 Freeter.AppImage "${pkgdir}"/opt/freeter
26 ln -sf /opt/freeter/Freeter.AppImage "${pkgdir}"/usr/bin/freeter
27}
28

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion