outline-client-appimage-git

maintainer maintuner · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt .deb binary from an S3 bucket (outline-releases) and extracts it directly into the package directory. The S3 bucket is operated by Jigsaw/Google (the official Outline project maintainers), so this is effectively the official release channel rather than a random personal host. However, S3 buckets can be misconfigured or taken over, and there is no GPG signature verification — only an MD5 checksum, which is cryptographically weak and provides minimal integrity assurance. The artifact is an executed binary (AppImage wrapped in a .deb), not pure data, so a compromised or substituted binary would result in code execution on the user's system. The use of 'stable' as a path component (rather than a pinned version hash) means the checksum could drift if the upstream file is replaced. This is a genuine, if modest, supply-chain concern: not clearly malicious, but the weak integrity check on an executed binary from a mutable S3 path warrants a medium rating.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source=("${_deb_base_name}.deb::https://s3.amazonaws.com/outline-releases/client/linux/stable/outline-client_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt .deb binary from an S3 bucket (outline-releases) and extracts it directly into the package directory. The S3 bucket is operated by Jigsaw/Google (the official Outline project maintainers), so this is effectively the official release channel rather than a random personal host. However, S3 buckets can be misconfigured or taken over, and there is no GPG signature verification — only an MD5 checksum, which is cryptographically weak and provides minimal integrity assurance. The artifact is an executed binary (AppImage wrapped in a .deb), not pure data, so a compromised or substituted binary would result in code execution on the user's system. The use of 'stable' as a path component (rather than a pinned version hash) means the checksum could drift if the upstream file is replaced. This is a genuine, if modest, supply-chain concern: not clearly malicious, but the weak integrity check on an executed binary from a mutable S3 path warrants a medium rating.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: maintuner <zackmelan>
2_deb_base_name=outline
3pkgname=outline-client-appimage-git
4pkgver=1.19.0
5pkgrel=1
6pkgdesc="The Outline clients use the popular Shadowsocks protocol, and lean on the Cordova and Electron frameworks."
7arch=(x86_64)
8conflicts=('outline-client-appimage' 'outline-client-appimage-wayland' 'outline-client-appimage-git')
9license=("Apache License 2.0")
10url="https://getoutline.org"
11
12
13#Outline-Client.AppImage::https://s3.amazonaws.com/outline-releases/client/linux/1.8.0/3/Outline-Client.AppImage"
14
15makedepends=('binutils' 'wget')
16
17source=("${_deb_base_name}.deb::https://s3.amazonaws.com/outline-releases/client/linux/stable/outline-client_amd64.deb")
18
19md5sums=('5b7c8d7ddbf8d03fab1ae9e576447bba')
20
21options=('!strip')
22
23package() {
24 ar x "${_deb_base_name}.deb"
25 tar -xf data.tar.xz -C "${pkgdir}"
26}
27

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion