jopdf

maintainer Uthopik · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from cdn.jopdf.com, which is the project's own CDN but not an independently auditable source (no GitHub releases, no distro-official mirror). The sha256sum is pinned, which mitigates silent replacement at the moment of packaging, but the URL points to a mutable path (jopdf-linux-amd64_setup.deb with no version in the filename), meaning the hash could become stale or the file could be swapped between package updates. The installed artifact is a closed-source proprietary binary executed directly on the user's system (/opt/jopdf/JOPDF), with shared libraries also marked executable. This is a classic medium-risk supply-chain pattern: not clearly malicious, but an unofficial/personal CDN hosting an opaque executable with no source availability and a mutable download URL. The EULA embedded in the PKGBUILD explicitly prohibits reverse engineering, making independent verification impossible. No piracy or broken flags apply.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("${pkgname}-${pkgver}.deb::https://cdn.jopdf.com/download/jopdf/jopdf-linux-amd64_setup.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from cdn.jopdf.com, which is the project's own CDN but not an independently auditable source (no GitHub releases, no distro-official mirror). The sha256sum is pinned, which mitigates silent replacement at the moment of packaging, but the URL points to a mutable path (jopdf-linux-amd64_setup.deb with no version in the filename), meaning the hash could become stale or the file could be swapped between package updates. The installed artifact is a closed-source proprietary binary executed directly on the user's system (/opt/jopdf/JOPDF), with shared libraries also marked executable. This is a classic medium-risk supply-chain pattern: not clearly malicious, but an unofficial/personal CDN hosting an opaque executable with no source availability and a mutable download URL. The EULA embedded in the PKGBUILD explicitly prohibits reverse engineering, making independent verification impossible. No piracy or broken flags apply.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Uthopik <josearrillaga@ik.me>
2pkgname=jopdf
3pkgver=2.2.0
4pkgrel=1
5pkgdesc="Free & Fast PDF Editor for Linux"
6arch=('x86_64')
7url="https://jopdf.com"
8license=('LicenseRef-EULA')
9depends=('hicolor-icon-theme' 'nss' 'libxss' 'gtk3' 'libxtst' 'alsa-lib' 'java-runtime' 'qt5-base')
10options=('!strip')
11
12source=("${pkgname}-${pkgver}.deb::https://cdn.jopdf.com/download/jopdf/jopdf-linux-amd64_setup.deb")
13sha256sums=('1bdf771893943a1e96b1b5dcc62af530aaec5059aa09fa80e01b6e03228cb327')
14
15package() {
16 # 1. Extracción del contenido
17 if [ -f "${srcdir}/data.tar.xz" ]; then
18 bsdtar -xf "${srcdir}/data.tar.xz" -C "${pkgdir}"
19 elif [ -f "${srcdir}/data.tar.zst" ]; then
20 bsdtar -xf "${srcdir}/data.tar.zst" -C "${pkgdir}"
21 fi
22
23 # 2. Corregir permisos (Sobre los archivos reales, ANTES de los links)
24 chown -R root:root "${pkgdir}"
25 find "${pkgdir}" -type d -exec chmod 755 {} +
26 find "${pkgdir}" -type f -exec chmod 644 {} +
27
28 # Dar ejecución al binario y librerías
29 chmod +x "${pkgdir}/opt/jopdf/JOPDF"
30 find "${pkgdir}/opt/jopdf/lib" -name "*.so*" -exec chmod +x {} +
31
32 # 3. Licencia
33 install -d "${pkgdir}/usr/share/licenses/${pkgname}"
34 cat <<EOF > "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
35
36End User License Agreement
37Read the JOPDF EULA to understand your rights and responsibilities when using our services.
38Last Updated August 27, 2025
39This License Agreement is a legal agreement between the end user (“Licensee”) and JOPDF (“Licensor”). Under this Agreement, the Licensor grants the Licensee a license to use the Licensed Software. By downloading, installing, accessing, or using our Services, you agree to be bound by the terms of this License Agreement and any other applicable agreements. If you do not agree to the terms, you have no right to the product and should not install, copy, download, access, or use it.
40
411. GRANT OF LICENSE
42JOPDF grants the Licensee a limited, non-exclusive, non-transferable, non-sublicensable, and revocable license to install and use the Services for the purchased period and solely for the Licensee’s private use.
43Any use or installation of more copies of the Licensed Software than are licensed is strictly prohibited without prior written consent from the Licensor. If the Licensee is authorized to distribute the Licensed Software within its organization, all restrictions in this License Agreement apply to each individual end user.
44
452. COPYRIGHT
46The Software is owned by JOPDF and is protected by international copyright laws and treaty provisions. The Licensee shall not remove or conceal any proprietary notices, labels, or marks from the Software.
47
483. OWNERSHIP
49The Licensor reserves all rights not expressly granted to the Licensee under this License Agreement. The rights granted are limited to the use of the Licensed Software and do not include any intellectual property rights of the Licensor or third parties.
50
514. LICENSE LIMITATIONS
52The Licensee may not:
53
54Create, use, share, or publish all or any portion of the Licensed Software or Documentation.
55Publish, copy, lease, or lend the Licensed Software.
56Reverse engineer, decompile, disassemble, or attempt to discover the source code of the Licensed Software.
57Modify, distort, disrupt, or slow down the normal functioning of all or part of the Licensed Software.
58Use the Licensed Software to host applications for third parties, or as part of facility management, timesharing, service provider, or service bureau arrangements.
59Transmit any virus, Trojan horse, worm, bomb, corrupted file, or use the Licensed Software in any illegal or unauthorized manner.
60
615. TERMINATION
62The term of this License Agreement corresponds to the License type and/or duration purchased, starting from the date of purchase, download, or account activation, until terminated according to its terms.
63
64At the end of the term, the Licensee must uninstall and permanently delete or destroy all but one copy of the Licensed Software within thirty (30) days of termination or expiration. This Agreement terminates automatically if the Licensee fails to comply with any terms or conditions. Upon termination for any reason, the Licensee shall return all copies of the Licensed Software to the Licensor or provide written confirmation that all copies have been destroyed.
65
666. NO WARRANTY ON LICENSED SOFTWAR
67SUBJECT TO APPLICABLE LAW, THE LICENSED SOFTWARE IS PROVIDED “AS IS.” THE LICENSOR, AND THE LICENSOR’S SUPPLIERS OR AFFILIATES, MAKE NO WARRANTY REGARDING ITS USE OR PERFORMANCE.
68
69THE LICENSOR AND ITS AFFILIATES DISCLAIM ALL WARRANTIES, CONDITIONS, REPRESENTATIONS, OR TERMS (EXPRESS OR IMPLIED, BY STATUTE, COMMON LAW, CUSTOM, USAGE, OR OTHERWISE), INCLUDING BUT NOT LIMITED TO WARRANTIES OF NON-INFRINGEMENT, MERCHANTABILITY, INTEGRATION, SATISFACTORY QUALITY, OR FITNESS FOR A PARTICULAR PURPOSE, EXCEPT WHERE SUCH WARRANTIES CANNOT BE EXCLUDED OR LIMITED BY APPLICABLE LAW IN THE LICENSEE’S JURISDICTION.
70EOF
71
72 # 4. Ajustar el archivo .desktop
73 sed -i 's|/opt/jopdf/JOPDF|jopdf|g' "${pkgdir}/usr/share/applications/jopdf.desktop"
74
75 # 5. Crear el enlace simbólico (AL FINAL)
76 # Lo creamos después del chmod para que no de error de "enlace colgado"
77 install -d "${pkgdir}/usr/bin"
78 ln -s /opt/jopdf/JOPDF "${pkgdir}/usr/bin/jopdf"
79}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion