mc-litematica-116-fabric

maintainer eatmyvenom · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD fetches a manifest JSON from masa.dy.fi with 'SKIP' checksum, then dynamically resolves and downloads a JAR file URL from that manifest at build time using wget — with no integrity verification whatsoever on the downloaded JAR. masa.dy.fi is the personal site of 'masa' (Matti Ruohonen), a well-known Minecraft modder who maintains litematica, so the host is not random/unknown. However, the pattern is still a genuine supply-chain concern: (1) the sha1sum is SKIP for the manifest, meaning any MITM or server compromise could redirect to an arbitrary JAR, (2) the JAR itself has no checksum at all, (3) the URL for the JAR is resolved dynamically at build time from the manifest, so the actual binary being installed is not pinned in any way. This is a real medium-severity supply-chain risk — an executed JAR from a personal host with no integrity verification — even though the host is a known mod author's site rather than a completely unknown one.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD fetches a manifest JSON from masa.dy.fi with 'SKIP' checksum, then dynamically resolves and downloads a JAR file URL from that manifest at build time using wget — with no integrity verification whatsoever on the downloaded JAR. masa.dy.fi is the personal site of 'masa' (Matti Ruohonen), a well-known Minecraft modder who maintains litematica, so the host is not random/unknown. However, the pattern is still a genuine supply-chain concern: (1) the sha1sum is SKIP for the manifest, meaning any MITM or server compromise could redirect to an arbitrary JAR, (2) the JAR itself has no checksum at all, (3) the URL for the JAR is resolved dynamically at build time from the manifest, so the actual binary being installed is not pinned in any way. This is a real medium-severity supply-chain risk — an executed JAR from a personal host with no integrity verification — even though the host is a known mod author's site rather than a completely unknown one.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
2
3_modname=litematica
4_mcver="1.16.4"
5pkgname=mc-litematica-116-fabric
6pkgver="0.0.0.dev.20210104.135541"
7pkgrel=1
8pkgdesc="A new schematic mod written from scratch"
9arch=('any')
10url="https://masa.dy.fi/mcmods/client_mods/"
11license=('LGPL')
12makedepends=('wget' 'jq')
13source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
14sha1sums=('SKIP')
15
16pkgver() {
17 cd $srcdir
18 cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
19}
20
21build() {
22 wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"url\"]")
23}
24
25package() {
26 install -d -m 755 "${pkgdir}/usr/share/minecraft"
27
28 cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"filename\"]") \
29 "${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.jar"
30}
31

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion