itchio-bin
maintainer TheRealOwenJ
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
Downloads a prebuilt binary from broth.itch.zone, which is itch.io's own official distribution infrastructure (used by the itch.io butler/broth toolchain), with a sha256 checksum provided; this is the project's own release channel, not an unrelated third-party host, so the risk is low despite the non-whitelisted domain.
Triggered rules
LOW
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Downloads a prebuilt binary from broth.itch.zone, which is itch.io's own official distribution infrastructure (used by the itch.io butler/broth toolchain), with a sha256 checksum provided; this is the project's own release channel, not an unrelated third-party host, so the risk is low despite the non-whitelisted domain.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:23
"itch-${pkgver}.tar.gz::https://broth.itch.zone/itch/linux-amd64/${pkgver}/archive/default"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: TheRealOwenJ <troj@newo.live>
2
3
pkgname=itchio-bin
4
pkgver=26.15.0
5
pkgrel=1
6
pkgdesc="The official desktop app for itch.io"
7
arch=('x86_64')
8
url="https://itch.io/app"
9
license=('MIT')
10
provides=('itchio')
11
conflicts=('itchio')
12
depends=(
13
'alsa-lib'
14
'gtk3'
15
'libxss'
16
'libxtst'
17
'nss'
18
'xdg-utils'
19
)
20
options=('!strip')
21
22
source=(
23
"itch-${pkgver}.tar.gz::https://broth.itch.zone/itch/linux-amd64/${pkgver}/archive/default"
24
)
25
26
sha256sums=(
27
'c5bc21f9584bb7802d5875ca5244483dae5360efbc6e39677b0bf497d2df8b10'
28
)
29
30
package() {
31
install -dm755 "${pkgdir}/opt/itch"
32
33
cp -a "${srcdir}"/* "${pkgdir}/opt/itch/"
34
35
install -dm755 "${pkgdir}/usr/bin"
36
37
ln -s "/opt/itch/itch" \
38
"${pkgdir}/usr/bin/itch"
39
40
install -Dm644 \
41
"${srcdir}/resources/app/src/static/images/window/itch/icon.png" \
42
"${pkgdir}/usr/share/icons/hicolor/256x256/apps/itch.png"
43
44
install -Dm644 \
45
"${srcdir}/LICENSE" \
46
"${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
47
48
install -Dm644 /dev/stdin \
49
"${pkgdir}/usr/share/applications/itch.desktop" <<EOF
50
[Desktop Entry]
51
Name=itch.io
52
Comment=The official desktop app for itch.io
53
Exec=itch %U
54
Icon=itch
55
Terminal=false
56
Type=Application
57
Categories=Game;
58
StartupWMClass=itch
59
EOF
60
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 3 |
| 2026-08-02 00:16:08 | LOW | 3 |
| 2026-08-01 00:11:18 | LOW | 3 |
| 2026-07-31 00:14:10 | LOW | 3 |
| 2026-07-30 00:17:23 | LOW | 3 |
| 2026-07-29 00:25:53 | LOW | 3 |
| 2026-07-28 00:07:28 | LOW | 3 |
| 2026-07-27 00:24:32 | LOW | 3 |
| 2026-07-26 00:07:32 | LOW | 3 |
| 2026-07-25 00:13:44 | LOW | 3 |
| 2026-07-24 00:02:28 | LOW | 3 |
| 2026-07-23 00:14:47 | LOW | 3 |
| 2026-07-22 00:29:32 | LOW | 3 |
| 2026-07-21 15:18:58 | LOW | 3 |
| 2026-07-21 15:17:04 | MEDIUM | 2 |