glesha-bin
Prebuilt binary downloaded from a personal/project-owned domain (packages.toxdes.com) that is not official infrastructure and could be silently swapped; checksums are present which mitigates but does not eliminate the risk of an unverifiable binary from a non-canonical host.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source_x86_64=("glesha-${pkgver}-x86_64.tar.gz::https://packages.toxdes.com/glesha/releases/glesha_${pkgver}_amd64.tar.gz")
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 75%): Prebuilt binary downloaded from a personal/project-owned domain (packages.toxdes.com) that is not official infrastructure and could be silently swapped; checksums are present which mitigates but does not eliminate the risk of an unverifiable binary from a non-canonical host.
PKGBUILD
1 offending line(s) highlighted# Maintainer: toxdes <hi@toxdes.com>
pkgname=glesha-bin
pkgver=0.5.1
pkgrel=1
pkgdesc="Encrypted archives and indexed cloud backups"
arch=('x86_64' 'aarch64')
url="https://github.com/toxdes/glesha"
license=('MIT')
depends=()
source_x86_64=("glesha-${pkgver}-x86_64.tar.gz::https://packages.toxdes.com/glesha/releases/glesha_${pkgver}_amd64.tar.gz")
sha256sums_x86_64=('df7f5da4a9caa5fd7a6f89e621e90fb2303bd86927f23a30206f942378621d63')
source_aarch64=("glesha-${pkgver}-aarch64.tar.gz::https://packages.toxdes.com/glesha/releases/glesha_${pkgver}_arm64.tar.gz")
sha256sums_aarch64=('2694de73e6f04b6220d58b851829e30d81c419b06ccd9cd1feb5638843b753ca')
package() {
bsdtar -xf "${srcdir}/glesha-${pkgver}-${CARCH}.tar.gz" -C "${pkgdir}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Medium | 3 |
| 2026-10-06 00:13:36 | Medium | 3 |
| 2026-10-05 23:40:58 | Medium | 3 |