minify-js-bin

maintainer charlottedurand · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt x86_64 binary from static.wilsonl.in (the author's personal CDN/static host) rather than from the project's GitHub releases page. The binary is installed directly as an executable. While the SHA-256 checksum is present and the domain appears to belong to the upstream author (wilsonzlin), this is still a supply-chain concern: the host is not the canonical forge, there is no GPG signature verification, and a compromise of that personal static host would deliver a malicious executable to users. This is a textbook medium-severity AUR pattern — executed binary from an unofficial/personal host with only a hash check.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:8 source_x86_64=("https://static.wilsonl.in/minify-js/cli/$pkgver/linux-$CARCH/minify-js")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt x86_64 binary from static.wilsonl.in (the author's personal CDN/static host) rather than from the project's GitHub releases page. The binary is installed directly as an executable. While the SHA-256 checksum is present and the domain appears to belong to the upstream author (wilsonzlin), this is still a supply-chain concern: the host is not the canonical forge, there is no GPG signature verification, and a compromise of that personal static host would deliver a malicious executable to users. This is a textbook medium-severity AUR pattern — executed binary from an unofficial/personal host with only a hash check.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: pitbuster <felipe.contreras.s@gmail.com>
2pkgname=minify-js-bin
3pkgver=0.5.6
4pkgrel=1
5pkgdesc='Extremely fast JavaScript minifier, written in Rust'
6url='https://github.com/wilsonzlin/minify-js'
7source=('LICENSE')
8source_x86_64=("https://static.wilsonl.in/minify-js/cli/$pkgver/linux-$CARCH/minify-js")
9arch=('x86_64')
10license=('MIT')
11depends=('gcc-libs')
12sha256sums=('a131d5418ac118f39e3b4478b30e3b1769c407fa389850abc422fc64c1675310')
13sha256sums_x86_64=('401b0c298c99da7bfa577b743b33f93a22cdfc52d1d11ba14b15f71b9810edb6')
14
15package() {
16 cd "$srcdir/"
17
18 install -Dm755 minify-js "${pkgdir}/usr/bin/minify-js"
19 install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion