msedgedriver-stable-bin

maintainer Jona · 1 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a prebuilt binary from Microsoft's official msedgedriver domain, which is plausibly the project's own release infrastructure, making it a standard and trusted source despite not being on a whitelist.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt binary from Microsoft's official msedgedriver domain, which is plausibly the project's own release infrastructure, making it a standard and trusted source despite not being on a whitelist.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:30 source=("${_pkgname}_${pkgver}_linux64.zip::https://msedgedriver.microsoft.com/${pkgver}/edgedriver_linux64.zip")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Triss Healy (trissylegs) <th@trissyle.gs>
2# Contributer: JunYoung Gwak <aur@jgwak.com>
3# Contributor: relrel <relrelbachar@gmail.com>
4# Contributor: grimsock <lord.grimsock at gmail dot com>
5# Contributor: James An <james@jamesan.ca>
6# Contributor: lybin
7# Contributor: Jonatan R. Fischer <jonafischer at gmail dot com>
8# Forked from chromedriver package
9_pkgname=msedgedriver
10_channel=stable
11pkgname=${_pkgname}-stable-bin
12pkgver=151.0.4129.59
13pkgrel=1
14pkgdesc="Standalone server that implements the W3C WebDriver standard (for microsoft edge)"
15arch=('x86_64')
16url="https://developer.microsoft.com/en-us/microsoft-edge/tools/webdriver/"
17license=('BSD' 'custom')
18depends=(glib2 nss xdg-utils)
19optdepends=(microsoft-edge-${_channel}=${pkgver}-${pkgrel})
20provides=("${_pkgname}=${pkgver}" "${_pkgname}-${_channel}")
21conflicts=(
22 "${_pkgname}"
23 "${_pkgname}-beta"
24 "${_pkgname}-dev"
25 "${_pkgname}-bin"
26 "${_pkgname}-beta-bin"
27 "${_pkgname}-dev-bin"
28)
29# eg https://msedgedriver.microsoft.com/148.0.3967.70/edgedriver_linux64.zip
30source=("${_pkgname}_${pkgver}_linux64.zip::https://msedgedriver.microsoft.com/${pkgver}/edgedriver_linux64.zip")
31sha512sums=('8a86126e103cd1a8d77eab51660c47ad32ef28fdd48bbb1dbe45ceec6764eb00172339bb37f00736afb2910ddba01186104cb4e9f159629b697fe5a0213bfe9f')
32
33package() {
34 install -Dm755 "${srcdir}/${_pkgname}" -t "${pkgdir}/usr/bin/"
35}
36

Changes since previous scan

--- PKGBUILD @ 2026-06-19 19:07
+++ PKGBUILD @ 2026-08-03 00:08
@@ -9,7 +9,7 @@
_pkgname=msedgedriver
_channel=stable
pkgname=${_pkgname}-stable-bin
-pkgver=148.0.3967.70
+pkgver=151.0.4129.59
pkgrel=1
pkgdesc="Standalone server that implements the W3C WebDriver standard (for microsoft edge)"
arch=('x86_64')
@@ -28,7 +28,7 @@
)
# eg https://msedgedriver.microsoft.com/148.0.3967.70/edgedriver_linux64.zip
source=("${_pkgname}_${pkgver}_linux64.zip::https://msedgedriver.microsoft.com/${pkgver}/edgedriver_linux64.zip")
-sha512sums=('114e75b9cc4ba59301c7d91b536e6c1b90a271e1863f2f8c214044754737b80ad86b2df4a54d5db7e87146fb200d8cd9fb716275e5eb390df67abe985dd67531')
+sha512sums=('8a86126e103cd1a8d77eab51660c47ad32ef28fdd48bbb1dbe45ceec6764eb00172339bb37f00736afb2910ddba01186104cb4e9f159629b697fe5a0213bfe9f')
package() {
install -Dm755 "${srcdir}/${_pkgname}" -t "${pkgdir}/usr/bin/"

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 09:20:18 MEDIUM 1
2026-06-19 19:07:35 CLEAN 2
2026-06-18 16:11:54 MEDIUM 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion