jriver-media-center24

LOW
maintainer orphaned 3 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is downloaded from files.jriver.com, which is the official JRiver distribution host. The SKIP checksum is sloppy and means the .deb cannot be verified against a known-good hash, but this is a common pattern for packages that track 'latest' builds where the upstream URL content changes. The binary is a prebuilt .deb from the vendor's own infrastructure, not a personal or third-party host. The risk is low: if JRiver's own server were compromised that would be an upstream supply-chain issue, not an AUR packaging attack. The missing checksum is a quality/hygiene issue rather than an active security threat. No obfuscation, no exfiltration, no unofficial host.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The source is downloaded from files.jriver.com, which is the official JRiver distribution host. The SKIP checksum is sloppy and means the .deb cannot be verified against a known-good hash, but this is a common pattern for packages that track 'latest' builds where the upstream URL content changes. The binary is a prebuilt .deb from the vendor's own infrastructure, not a personal or third-party host. The risk is low: if JRiver's own server were compromised that would be an upstream supply-chain issue, not an AUR packaging attack. The missing checksum is a quality/hygiene issue rather than an active security threat. No obfuscation, no exfiltration, no unofficial host.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("http://files.jriver.com/mediacenter/channels/v24/latest/MediaCenter-$_debpkgver-amd64.deb" 'License.txt')

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: AudioLinux <audiolinux AT fastmail DOT fm>
2
3pkgname=jriver-media-center24
4_debpkgver=24.0.78
5pkgver=24.0.78
6pkgrel=1
7pkgdesc="The Most Comprehensive Media Software"
8arch=('x86_64')
9url="http://www.jriver.com/"
10license=('custom')
11depends=('alsa-lib' 'gcc-libs' 'libx11' 'libxext' 'libxcb' 'libxau' 'libxdmcp' 'util-linux' 'libxext' 'gtk3' 'webkit2gtk' 'gstreamer' 'gst-plugins-base' 'gst-plugins-base-libs' 'gst-plugins-good' 'gst-plugins-ugly' 'gst-libav')
12optdepends=('mesa-libgl: nouveau video support' 'nvidia-libgl: nvidia video support' 'vorbis-tools' 'musepack-tools')
13conflicts=('jriver-media-center')
14source=("http://files.jriver.com/mediacenter/channels/v24/latest/MediaCenter-$_debpkgver-amd64.deb" 'License.txt')
15sha256sums=('SKIP' 'ee00f430918df6be37777a61e12812875b5583379c78daaa969bae7383a41fbd')
16
17package() {
18 cd "$srcdir"
19 bsdtar xf data.tar.xz -C "$pkgdir"
20 install -Dm644 "License.txt" \
21 "$pkgdir/usr/share/licenses/$pkgname/COPYING"
22}
23

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion