libps4000
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=("http://labs.picotech.com/debian/pool/main/libp/libps4000/${pkgname}_${pkgver//_/-}_amd64.deb")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from labs.picotech.com, which is PicoTech's official Linux software distribution host (they publish their Linux drivers/libraries there). The domain is plausibly legitimate — PicoTech is a real oscilloscope manufacturer and labs.picotech.com is their known Linux package repository. However, the package installs a prebuilt closed-source binary library directly from a vendor-controlled host without any signature verification (only an MD5 checksum, which provides integrity but not authenticity). This is a real supply-chain concern: if the host were compromised or the binary swapped, the MD5 would not catch it. The pattern (vendor binary .deb repackaged for Arch) is common in the AUR for hardware vendors, but the lack of GPG/SHA256 verification and the closed-source nature of the binary keep this at medium rather than clean.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Mikael Tillenius <mti at tillenius dot com>
pkgname=libps4000
pkgver=2.1.54_2r2438
pkgrel=1
pkgdesc="library for picotech oscilloscope 4000 series (4223, 4224, 4226, 4227, 4262, 4423, 4424)"
arch=('x86_64')
url="http://www.picotech.com/linux.html"
license=('custom')
groups=()
depends=(libusb)
optdepends=()
provides=()
conflicts=()
replaces=()
backup=()
options=(!strip)
install=
changelog=
source=("http://labs.picotech.com/debian/pool/main/libp/libps4000/${pkgname}_${pkgver//_/-}_amd64.deb")
md5sums=('31fa2c4d7c3bb079ed149ff54ab79ec2')
package() {
tar -xf data.tar.xz -C "${pkgdir}"
chmod -R go-w $pkgdir
chown -R root:root $pkgdir
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |