msedgedriver-stable-bin

LOW
maintainer Jona 1 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a prebuilt binary from Microsoft's official msedgedriver domain, which is plausibly the project's own release infrastructure, making it a standard and trusted source despite not being on a whitelist.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt binary from Microsoft's official msedgedriver domain, which is plausibly the project's own release infrastructure, making it a standard and trusted source despite not being on a whitelist.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:30 source=("${_pkgname}_${pkgver}_linux64.zip::https://msedgedriver.microsoft.com/${pkgver}/edgedriver_linux64.zip")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Triss Healy (trissylegs) <th@trissyle.gs>
2# Contributer: JunYoung Gwak <aur@jgwak.com>
3# Contributor: relrel <relrelbachar@gmail.com>
4# Contributor: grimsock <lord.grimsock at gmail dot com>
5# Contributor: James An <james@jamesan.ca>
6# Contributor: lybin
7# Contributor: Jonatan R. Fischer <jonafischer at gmail dot com>
8# Forked from chromedriver package
9_pkgname=msedgedriver
10_channel=stable
11pkgname=${_pkgname}-stable-bin
12pkgver=151.0.4129.59
13pkgrel=1
14pkgdesc="Standalone server that implements the W3C WebDriver standard (for microsoft edge)"
15arch=('x86_64')
16url="https://developer.microsoft.com/en-us/microsoft-edge/tools/webdriver/"
17license=('BSD' 'custom')
18depends=(glib2 nss xdg-utils)
19optdepends=(microsoft-edge-${_channel}=${pkgver}-${pkgrel})
20provides=("${_pkgname}=${pkgver}" "${_pkgname}-${_channel}")
21conflicts=(
22 "${_pkgname}"
23 "${_pkgname}-beta"
24 "${_pkgname}-dev"
25 "${_pkgname}-bin"
26 "${_pkgname}-beta-bin"
27 "${_pkgname}-dev-bin"
28)
29# eg https://msedgedriver.microsoft.com/148.0.3967.70/edgedriver_linux64.zip
30source=("${_pkgname}_${pkgver}_linux64.zip::https://msedgedriver.microsoft.com/${pkgver}/edgedriver_linux64.zip")
31sha512sums=('8a86126e103cd1a8d77eab51660c47ad32ef28fdd48bbb1dbe45ceec6764eb00172339bb37f00736afb2910ddba01186104cb4e9f159629b697fe5a0213bfe9f')
32
33package() {
34 install -Dm755 "${srcdir}/${_pkgname}" -t "${pkgdir}/usr/bin/"
35}
36

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion