mod_authn_otp

maintainer chrbayer · 2 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The source tarball is fetched from an Amazon S3 bucket under a personal/project namespace (archie-public) rather than from the official GitHub releases page for the same project (https://github.com/archiecobbs/mod-authn-otp). While the project author (archiecobbs) likely controls this S3 bucket, it is not the canonical upstream release host and there is no guarantee of integrity beyond the sha256sum. The package compiles and installs a native Apache authentication module (.so), meaning any tampered source would result in executed privileged code loaded into the Apache web server process. The sha256sum provides some protection against accidental corruption but not against a deliberate substitution at the S3 host. The correct packaging practice would be to pull from GitHub releases or tags. This is a genuine medium-severity supply-chain concern: compiled native code from a non-canonical host, not clearly malicious but not clean either.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("https://s3.amazonaws.com/archie-public/mod-authn-otp/${pkgname}-${pkgver}.tar.gz")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The source tarball is fetched from an Amazon S3 bucket under a personal/project namespace (archie-public) rather than from the official GitHub releases page for the same project (https://github.com/archiecobbs/mod-authn-otp). While the project author (archiecobbs) likely controls this S3 bucket, it is not the canonical upstream release host and there is no guarantee of integrity beyond the sha256sum. The package compiles and installs a native Apache authentication module (.so), meaning any tampered source would result in executed privileged code loaded into the Apache web server process. The sha256sum provides some protection against accidental corruption but not against a deliberate substitution at the S3 host. The correct packaging practice would be to pull from GitHub releases or tags. This is a genuine medium-severity supply-chain concern: compiled native code from a non-canonical host, not clearly malicious but not clean either.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Christoph Bayer <chrbayer@criby.de>
2
3pkgname=mod_authn_otp
4pkgver=1.1.10
5pkgrel=1
6pkgdesc='Apache module for one time password authentication'
7arch=('i686' 'x86_64')
8url='https://github.com/archiecobbs/mod-authn-otp'
9license=('Apache')
10depends=('openssl')
11makedepends=('apache')
12source=("https://s3.amazonaws.com/archie-public/mod-authn-otp/${pkgname}-${pkgver}.tar.gz")
13sha256sums=('043f305d26f33ef01b43136bce8f7814bdffd4627a36ab147da46b1852c5f3e7')
14
15package() {
16 cd $srcdir/${pkgname}-${pkgver}
17 ./configure
18 make || return 1
19 mkdir -p "${pkgdir}/usr/lib/httpd/modules/"
20 make DESTDIR="${pkgdir}" install
21}
22

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion