itchio-bin

LOW
maintainer TheRealOwenJ 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

Downloads a prebuilt binary from broth.itch.zone, which is itch.io's own official distribution infrastructure (used by the itch.io butler/broth toolchain), with a sha256 checksum provided; this is the project's own release channel, not an unrelated third-party host, so the risk is low despite the non-whitelisted domain.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Downloads a prebuilt binary from broth.itch.zone, which is itch.io's own official distribution infrastructure (used by the itch.io butler/broth toolchain), with a sha256 checksum provided; this is the project's own release channel, not an unrelated third-party host, so the risk is low despite the non-whitelisted domain.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:23 "itch-${pkgver}.tar.gz::https://broth.itch.zone/itch/linux-amd64/${pkgver}/archive/default"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: TheRealOwenJ <troj@newo.live>
2
3pkgname=itchio-bin
4pkgver=26.15.0
5pkgrel=1
6pkgdesc="The official desktop app for itch.io"
7arch=('x86_64')
8url="https://itch.io/app"
9license=('MIT')
10provides=('itchio')
11conflicts=('itchio')
12depends=(
13 'alsa-lib'
14 'gtk3'
15 'libxss'
16 'libxtst'
17 'nss'
18 'xdg-utils'
19)
20options=('!strip')
21
22source=(
23 "itch-${pkgver}.tar.gz::https://broth.itch.zone/itch/linux-amd64/${pkgver}/archive/default"
24)
25
26sha256sums=(
27 'c5bc21f9584bb7802d5875ca5244483dae5360efbc6e39677b0bf497d2df8b10'
28)
29
30package() {
31 install -dm755 "${pkgdir}/opt/itch"
32
33 cp -a "${srcdir}"/* "${pkgdir}/opt/itch/"
34
35 install -dm755 "${pkgdir}/usr/bin"
36
37 ln -s "/opt/itch/itch" \
38 "${pkgdir}/usr/bin/itch"
39
40 install -Dm644 \
41 "${srcdir}/resources/app/src/static/images/window/itch/icon.png" \
42 "${pkgdir}/usr/share/icons/hicolor/256x256/apps/itch.png"
43
44 install -Dm644 \
45 "${srcdir}/LICENSE" \
46 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
47
48 install -Dm644 /dev/stdin \
49 "${pkgdir}/usr/share/applications/itch.desktop" <<EOF
50[Desktop Entry]
51Name=itch.io
52Comment=The official desktop app for itch.io
53Exec=itch %U
54Icon=itch
55Terminal=false
56Type=Application
57Categories=Game;
58StartupWMClass=itch
59EOF
60}

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion