iscfpc-aarch64

maintainer rarnu · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The package downloads a prebuilt binary tarball (aarch64 architecture-specific, no source build) from a personal/unofficial host (yugioh.vip:9000) that has no relationship to the stated upstream (github.com/isyscore/isc-fpbase). The tarball is then installed directly to /usr/bin via 'make install'. There is no source code compilation, no reproducibility, and the host is a non-standard server running on port 9000 with no verifiable provenance. The MD5 checksum provides minimal integrity protection (MD5 is cryptographically broken and the host controls both the file and could update the checksum). This is a genuine supply-chain concern: a prebuilt binary from an unofficial host is executed/installed on the target system, matching the medium severity definition exactly.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=("http://yugioh.vip:9000/static/$pkgname-$pkgver.tar.gz")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The package downloads a prebuilt binary tarball (aarch64 architecture-specific, no source build) from a personal/unofficial host (yugioh.vip:9000) that has no relationship to the stated upstream (github.com/isyscore/isc-fpbase). The tarball is then installed directly to /usr/bin via 'make install'. There is no source code compilation, no reproducibility, and the host is a non-standard server running on port 9000 with no verifiable provenance. The MD5 checksum provides minimal integrity protection (MD5 is cryptographically broken and the host controls both the file and could update the checksum). This is a genuine supply-chain concern: a prebuilt binary from an unofficial host is executed/installed on the target system, matching the medium severity definition exactly.

PKGBUILD

1 offending line(s) highlighted
1pkgname=iscfpc-aarch64
2pkgver=1.0.10
3pkgrel=20
4pkgdesc="project maintain tool for FreePascal"
5arch=('aarch64')
6url=https://github.com/isyscore/isc-fpbase
7license=('MPL')
8depends=()
9source=("http://yugioh.vip:9000/static/$pkgname-$pkgver.tar.gz")
10noextract=()
11md5sums=('5716bd8d1696503f99cdbc61b55c4d08')
12validpgpkeys=()
13
14package() {
15 cd "$srcdir"
16 if [ ! -d "$pkgdir/usr/bin" ]; then
17 mkdir -p "$pkgdir/usr/bin"
18 fi
19 make DESTDIR="$pkgdir" install
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion