libjasmin-easycrypt-bin
The package downloads a prebuilt Debian binary from a non-standard, project-specific repository domain (repo.formosa-crypto.org), which is not on common trust whitelists and could allow supply-chain tampering with an unverifiable executable artifact.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:24
"${_pkgname}_${_debver}_amd64.deb::https://repo.formosa-crypto.org/debian/pool/main/j/jasmin-compiler/${_pkgname}_${_debver}_amd64.deb"
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt Debian binary from a non-standard, project-specific repository domain (repo.formosa-crypto.org), which is not on common trust whitelists and could allow supply-chain tampering with an unverifiable executable artifact.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Davide Carnemolla <herbrant@protonmail.com>
pkgname=libjasmin-easycrypt-bin
pkgver=2026.03.2
pkgrel=2
pkgdesc="EasyCrypt libraries used for verifying Jasmin implementations"
arch=('x86_64')
url="https://github.com/jasmin-lang/jasmin"
license=('MIT')
# Runtime dependencies available in official repositories
depends=()
# Tools required to extract the Debian package
makedepends=('binutils' 'tar')
# Debian packages
_pkgname=libjasmin-easycrypt
# Debian package version (may include dashes, unlike pkgver)
_debver="${pkgver}-1"
source=(
"${_pkgname}_${_debver}_amd64.deb::https://repo.formosa-crypto.org/debian/pool/main/j/jasmin-compiler/${_pkgname}_${_debver}_amd64.deb"
"LICENSE-${pkgver}::https://raw.githubusercontent.com/jasmin-lang/jasmin/v${pkgver}/LICENSE"
)
sha256sums=('69259f903a31470d4f5f9f8b96af78ce3e24aea76b36b1e355e8dad6a5d0aa48'
'c7232c2cda11e4270104f2fd4bfbc7b368f536ad58271a9ad2775d1000aefc05')
package() {
cd "$srcdir"
# Extract the Debian package
ar x "${_pkgname}_${_debver}_amd64.deb"
# Extract data archive (format may vary)
if [ -f data.tar.xz ]; then
tar -xf data.tar.xz -C "$pkgdir"
elif [ -f data.tar.gz ]; then
tar -xf data.tar.gz -C "$pkgdir"
elif [ -f data.tar.zst ]; then
tar -xf data.tar.zst -C "$pkgdir"
fi
# The Debian copyright file is empty, so ship the upstream MIT license text
install -Dm644 "$srcdir/LICENSE-${pkgver}" \
"$pkgdir/usr/share/licenses/$pkgname/LICENSE"
# Drop the Debian documentation directory (empty copyright + changelog)
rm -rf "$pkgdir/usr/share/doc"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |