libps4000

maintainer mti · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from labs.picotech.com, which is PicoTech's official Linux software distribution host (they publish their Linux drivers/libraries there). The domain is plausibly legitimate — PicoTech is a real oscilloscope manufacturer and labs.picotech.com is their known Linux package repository. However, the package installs a prebuilt closed-source binary library directly from a vendor-controlled host without any signature verification (only an MD5 checksum, which provides integrity but not authenticity). This is a real supply-chain concern: if the host were compromised or the binary swapped, the MD5 would not catch it. The pattern (vendor binary .deb repackaged for Arch) is common in the AUR for hardware vendors, but the lack of GPG/SHA256 verification and the closed-source nature of the binary keep this at medium rather than clean.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:19 source=("http://labs.picotech.com/debian/pool/main/libp/libps4000/${pkgname}_${pkgver//_/-}_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from labs.picotech.com, which is PicoTech's official Linux software distribution host (they publish their Linux drivers/libraries there). The domain is plausibly legitimate — PicoTech is a real oscilloscope manufacturer and labs.picotech.com is their known Linux package repository. However, the package installs a prebuilt closed-source binary library directly from a vendor-controlled host without any signature verification (only an MD5 checksum, which provides integrity but not authenticity). This is a real supply-chain concern: if the host were compromised or the binary swapped, the MD5 would not catch it. The pattern (vendor binary .deb repackaged for Arch) is common in the AUR for hardware vendors, but the lack of GPG/SHA256 verification and the closed-source nature of the binary keep this at medium rather than clean.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Mikael Tillenius <mti at tillenius dot com>
2pkgname=libps4000
3pkgver=2.1.54_2r2438
4pkgrel=1
5pkgdesc="library for picotech oscilloscope 4000 series (4223, 4224, 4226, 4227, 4262, 4423, 4424)"
6arch=('x86_64')
7url="http://www.picotech.com/linux.html"
8license=('custom')
9groups=()
10depends=(libusb)
11optdepends=()
12provides=()
13conflicts=()
14replaces=()
15backup=()
16options=(!strip)
17install=
18changelog=
19source=("http://labs.picotech.com/debian/pool/main/libp/libps4000/${pkgname}_${pkgver//_/-}_amd64.deb")
20md5sums=('31fa2c4d7c3bb079ed149ff54ab79ec2')
21
22package() {
23 tar -xf data.tar.xz -C "${pkgdir}"
24 chmod -R go-w $pkgdir
25 chown -R root:root $pkgdir
26}
27

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion