hybrid-encoder
The package downloads a prebuilt binary from a non-whitelisted host (selur.de), which is not a standard code or release hosting platform, posing a moderate supply chain risk if the host were compromised or the download redirected.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:37
source_x86_64=(https://www.selur.de/files/hybrid_downloads/Hybrid_${pkgver}_64bit_binary_qt642.zip
llm_review
An AI model (qwen/qwen3-235b-a22b-07-25) reviewed this and agrees it is MEDIUM (confidence 85%): The package downloads a prebuilt binary from a non-whitelisted host (selur.de), which is not a standard code or release hosting platform, posing a moderate supply chain risk if the host were compromised or the download redirected.
PKGBUILD
1 offending line(s) highlighted# Maintainer: JohnyRi <honza dot rindt at gmail dot com>
# Contributor: Hugo Osvaldo Barrera <hugo at osvaldobarrera dot com dot ar>
pkgname=hybrid-encoder
pkgver=20260321
pkgrel=1
pkgdesc="A very complete gui for video encoding"
arch=('x86_64')
options=(!strip)
license=('custom')
depends=('framecounter' 'freetype2' 'glib2' 'openssl' 'qt6-multimedia')
optdepends=('aften: support for AC-3 audio encoding'
'bdsup2subpp-git: support for subtitle converison for image based stream formats'
'dcaenc: support for DTS audio encoding'
'delaycut: AC-3, DTS, MPA and WAV audio delay and cutting support'
'divx265: support for H.265 video encoding'
'fdkaac: support for AAC audio encoding'
'flac: support for lossless FLAC audio encoding'
'gpac: support for MP4 container muxing'
'kvazaar: support for H.265 video encoding'
'libvpx: support fot VP8 video encoding'
'lsdvd: support for listing the content of DVD disks'
'mediainfo: support for technical and tag information about a video or audio file'
'mencoder: support for video and audio encoding'
'mkvtoolnix-cli: support for MKV container muxing'
'mp4fpsmod: support for MP4 time code modification'
'mplayer: support for video preview'
'neroaacenc: support for NERO AAC audio encoding'
'opus-tools: support for Opus audio encoding'
'sox: support for processing of audio files'
'tsmuxer: support for TS container'
'vapoursynth: A video processing framework with the future in mind'
'x264: support for H.264 video encoding'
'x265: support for H.265 video encoding')
url="http://www.selur.de/"
source_x86_64=(https://www.selur.de/files/hybrid_downloads/Hybrid_${pkgver}_64bit_binary_qt642.zip
hybrid.desktop
Hybrid.png
LICENSE)
package() {
cd "${srcdir}"
install -D -m755 Hybrid "${pkgdir}"/usr/bin/Hybrid
install -D -m644 hybrid.desktop "${pkgdir}"/usr/share/applications/hybrid.desktop
install -D -m644 Hybrid.png "${pkgdir}"/usr/share/pixmaps/Hybrid.png
install -D -m644 LICENSE "$pkgdir"/usr/share/licenses/$pkgname/LICENSE
}
sha256sums_x86_64=('a4691620e127a9da26a0968002ba5b4725e6b27b29f273c05b781ca7d8bfc6a8'
'5052a2a78a1d3dc5a2b20b352e9aa01bbc2d9afd0da28de604e970acc216384c'
'4b62792db9e95bb0e4c0969e72001b146b55e5e6af91df81c404d6ef61dd633f'
'9b56b57bb0cec33e3964c953f6340004476aad346d9a50dc93b8389ab083c015')
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |