humble-trove

maintainer td512 · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary from a personal/unofficial CDN host (ltscdn.m6.nz) and installs it directly as an executable. The upstream project is on GitHub (td512/Humble-Trove-Console-Downloader) but the binary is not fetched from GitHub releases or any official distribution channel — it comes from a third-party host controlled by the maintainer. There is a sha256sum check, which mitigates tampering if the hash is correct, but the host itself is not an official or verifiable upstream source. If the host is compromised or the maintainer changes the binary without updating the PKGBUILD, users would execute arbitrary code. This is a classic supply-chain concern: executed binary from an unofficial personal host, not clearly malicious but a real risk.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=("trove::https://ltscdn.m6.nz/humble/1804/trove")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt binary from a personal/unofficial CDN host (ltscdn.m6.nz) and installs it directly as an executable. The upstream project is on GitHub (td512/Humble-Trove-Console-Downloader) but the binary is not fetched from GitHub releases or any official distribution channel — it comes from a third-party host controlled by the maintainer. There is a sha256sum check, which mitigates tampering if the hash is correct, but the host itself is not an official or verifiable upstream source. If the host is compromised or the maintainer changes the binary without updating the PKGBUILD, users would execute arbitrary code. This is a classic supply-chain concern: executed binary from an unofficial personal host, not clearly malicious but a real risk.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Theo Morra <theo@theom.nz>
2
3pkgname=humble-trove
4pkgver=1
5pkgrel=1
6license=('MIT')
7pkgdesc="The cross platform Humble Trove Downloader"
8arch=('x86_64')
9url="https://github.com/td512/Humble-Trove-Console-Downloader"
10source=("trove::https://ltscdn.m6.nz/humble/1804/trove")
11sha256sums=('32cb5bdf271a39421f0453508dd80779dee047621caa97e56e435844256003dd')
12
13package() {
14 install -Dm755 ./trove "${pkgdir}"/usr/bin/trove
15}
16

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion