katawa-shoujo-bin
The package downloads a prebuilt binary archive (containing a Ren'Py engine binary and Python libraries that are executed at runtime) from cdn.fhs.sh, which is not the official upstream host (katawa-shoujo.com). The official KS Linux download is distributed directly from the Four Leaf Studios site or mirrors like itch.io/lemmasoft, not cdn.fhs.sh. This is a personal/unofficial CDN operated by the maintainer or a third party, meaning the binary could be substituted without upstream's knowledge. A sha256 checksum is present, which mitigates tampering after the fact but does not establish trust in the source host itself — if the CDN is compromised or the maintainer rotates the file, the checksum would need to be updated. The installed content includes a native Linux x86_64 binary (the Ren'Py launcher) and Python libraries, all of which are executed on the user's system. This is a genuine supply-chain concern: executed binaries from an unofficial host. The piracy flag does not apply since Katawa Shoujo is a free, legally distributed game under CC-BY-NC-ND-3.0.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:20
"ks.tar.zst::https://cdn.fhs.sh/ks/bin/${pkgver}/%5B4ls%5D_katawa_shoujo_${pkgver}-%5Blinux-x86%5D%5BBA993979%5D.tar.zst"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The package downloads a prebuilt binary archive (containing a Ren'Py engine binary and Python libraries that are executed at runtime) from cdn.fhs.sh, which is not the official upstream host (katawa-shoujo.com). The official KS Linux download is distributed directly from the Four Leaf Studios site or mirrors like itch.io/lemmasoft, not cdn.fhs.sh. This is a personal/unofficial CDN operated by the maintainer or a third party, meaning the binary could be substituted without upstream's knowledge. A sha256 checksum is present, which mitigates tampering after the fact but does not establish trust in the source host itself — if the CDN is compromised or the maintainer rotates the file, the checksum would need to be updated. The installed content includes a native Linux x86_64 binary (the Ren'Py launcher) and Python libraries, all of which are executed on the user's system. This is a genuine supply-chain concern: executed binaries from an unofficial host. The piracy flag does not apply since Katawa Shoujo is a free, legally distributed game under CC-BY-NC-ND-3.0.
PKGBUILD
1 offending line(s) highlighted# Maintainer: snit <snit@cock.li>
# Contributor: Alice Jenkinson <virtual.aur at zero-x dot nz>
_pkgname="katawa-shoujo"
pkgname="$_pkgname-bin"
pkgver=1.3.2
pkgrel=1
pkgdesc="A bishoujo-style visual novel by Four Leaf Studios"
url="https://www.katawa-shoujo.com"
license=("CC-BY-NC-ND-3.0")
arch=("x86_64")
provides=("$_pkgname=$pkgver")
conflicts=("$_pkgname")
options=("!strip")
_pkgsrc="Katawa Shoujo-$pkgver-linux"
source=(
"ks.tar.zst::https://cdn.fhs.sh/ks/bin/${pkgver}/%5B4ls%5D_katawa_shoujo_${pkgver}-%5Blinux-x86%5D%5BBA993979%5D.tar.zst"
"katawa-shoujo.png"
)
sha256sums=(
'c76b644b9d7582b20c50d0a984e426b6a85d8c564325e73ad29637210e31e0af'
'dcd08ef958f785ac52b88a255680e385051d6b6a9626e57f00acb44021d7c0ee'
)
package() {
cd "$_pkgsrc"
# main files
install -dm755 "$pkgdir/usr/share/$_pkgname"
cp --reflink=auto -a game renpy "Katawa Shoujo.py" "$pkgdir/usr/share/$_pkgname/"
install -dm755 "$pkgdir/usr/share/$_pkgname/lib"
cp --reflink=auto -a lib/linux-x86_64 lib/pythonlib2.7 "$pkgdir/usr/share/$_pkgname/lib/"
# script
install -Dm755 /dev/stdin "$pkgdir/usr/bin/$_pkgname" << END
#!/bin/sh
BASE="/usr/share/katawa-shoujo"
LIB="\$BASE/lib/linux-x86_64"
BASEFILE="Katawa Shoujo"
exec "\$LIB/\$BASEFILE" \$RENPY_PYARGS -EO "\$BASE/\$BASEFILE.py" "\$@"
END
install -Dm644 /dev/stdin "$pkgdir/usr/share/applications/$_pkgname.desktop" << END
[Desktop Entry]
Name=Katawa Shoujo
Comment=$pkgdesc
Exec=$_pkgname
Icon=$_pkgname
Type=Application
Categories=Game;
END
# icon
install -Dm644 "$srcdir/$_pkgname.png" -t "$pkgdir/usr/share/pixmaps/"
# license
install -Dm644 LICENSE.txt "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
# manual
install -Dm644 'Game Manual.pdf' "$pkgdir/usr/share/doc/$pkgname/gamemanual.pdf"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |