hqplayer5

maintainer blackhole · 2 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt x86_64 binary (.deb) from signalyst.com, which is the official vendor website for HQPlayer (a commercial audio player by Signalyst). The binary is extracted and installed directly without compilation. While signalyst.com is the legitimate upstream vendor site (not a personal or unofficial host), the package installs a closed-source, prebuilt binary that users must trust entirely. A SHA-256 checksum is provided, which guards against accidental corruption but not against the vendor silently replacing the binary at the same URL. This is a standard pattern for proprietary software packaged in the AUR (similar to spotify, slack, zoom, etc.), and signalyst.com is the canonical distribution point for HQPlayer. The medium rating is borderline: it is a prebuilt binary from a commercial vendor's own site with a checksum, which is the normal AUR pattern for proprietary apps. However, since it is an executed binary from a non-open-source host with no reproducibility, the medium classification is defensible rather than clearly wrong.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("https://www.signalyst.com/bins/noble/hqplayer5desktop_"$_debpkgver"_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt x86_64 binary (.deb) from signalyst.com, which is the official vendor website for HQPlayer (a commercial audio player by Signalyst). The binary is extracted and installed directly without compilation. While signalyst.com is the legitimate upstream vendor site (not a personal or unofficial host), the package installs a closed-source, prebuilt binary that users must trust entirely. A SHA-256 checksum is provided, which guards against accidental corruption but not against the vendor silently replacing the binary at the same URL. This is a standard pattern for proprietary software packaged in the AUR (similar to spotify, slack, zoom, etc.), and signalyst.com is the canonical distribution point for HQPlayer. The medium rating is borderline: it is a prebuilt binary from a commercial vendor's own site with a checksum, which is the normal AUR pattern for proprietary apps. However, since it is an executed binary from a non-open-source host with no reproducibility, the medium classification is defensible rather than clearly wrong.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: AudioLinux <audiolinux AT fastmail DOT fm>
2
3pkgname=hqplayer5
4pkgver=5.17.2
5_debpkgver=5.17.2-47
6pkgrel=1
7pkgdesc="The high-end upsampling multichannel software HD-audio player"
8arch=('x86_64')
9url="http://www.signalyst.com/consumer.html"
10license=('custom')
11depends=('glibc' 'gcc-libs' 'libx11' 'libusb-compat' 'openmp' 'qt6-base' 'qt6-charts' 'libmicrohttpd' 'alsa-lib' 'flac' 'wavpack' 'mpg123')
12optdepends=('hqplayer-client' 'evince: hqplayer manual reading')
13conflicts=('hqplayer4')
14source=("https://www.signalyst.com/bins/noble/hqplayer5desktop_"$_debpkgver"_amd64.deb")
15sha256sums=('2973094e6c5bd5859c56b8b70ba57d8c373701326c3691e538781401d2caceb9')
16options=(!strip)
17install=${pkgname}.install
18
19package() {
20cd $srcdir
21bsdtar xf data.tar.zst -C "$pkgdir"
22install -Dm644 "$pkgdir/usr/share/doc/hqplayer5desktop/copyright" "$pkgdir/usr/share/licenses/$pkgname/COPYING"
23rm "$pkgdir/usr/share/doc/hqplayer5desktop/copyright"
24rm $pkgdir/usr/bin/hqplayer5client
25rm $pkgdir/usr/share/applications/hqplayer5client.desktop
26rm $pkgdir/usr/share/pixmaps/hqplayer5client.png
27}
28

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion