oxwu

MEDIUM
maintainer holishing 1 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads a prebuilt AppImage from a non-standard host (eew.earthquake.tw), which is not a common code hosting platform, and the checksum is provided but the source is not verifiable or rebuildable, posing a supply-chain risk if the host is compromised.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=("oxwu-$pkgver.AppImage::https://eew.earthquake.tw/releases/linux/x64/oxwu-linux-x86_64.AppImage")
Medium AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt AppImage from a non-standard host (eew.earthquake.tw), which is not a common code hosting platform, and the checksum is provided but the source is not verifiable or rebuildable, posing a supply-chain risk if the host is compromised.

PKGBUILD

1 offending line(s) highlighted
1# Contributor: holishing
2# Contributor: axzxc1236
3pkgname=oxwu
4pkgver=4.2.0
5pkgrel=1
6pkgdesc="The GUI software using P2P networking to fastly report Earthquakes in Taiwan"
7arch=('x86_64')
8url="https://eew.earthquake.tw"
9source=("oxwu-$pkgver.AppImage::https://eew.earthquake.tw/releases/linux/x64/oxwu-linux-x86_64.AppImage")
10sha512sums=('a7ab9967f632e545569a71ce8a5d9b12197a8d3d6ac8f8698de2700744d22162b08baf6b8242f12fb1e9c716aebe4bb529900cc37cf8749e6696d7e3d0397c94')
11noextract=("oxwu-$pkgver.AppImage")
12options+=('!strip')
13
14prepare() {
15 cd "${srcdir}"
16 # Extract appimage content
17 chmod +x oxwu-$pkgver.AppImage
18 ./oxwu-$pkgver.AppImage --appimage-extract > /dev/null
19 # Fix permissions; .AppImage permissions are 700 for all directories
20 chmod -R a-x+rX squashfs-root/usr
21}
22
23build() {
24 # Adjust .desktop so it will work outside of AppImage container
25 sed -i -E 's|Exec=AppRun|Exec=env DESKTOPINTEGRATION=false /opt/OXWU/oxwu.AppImage|' 'squashfs-root/oxwu.desktop'
26}
27
28package() {
29 install -Dm755 "${srcdir}/oxwu-$pkgver.AppImage" "${pkgdir}/opt/OXWU/oxwu.AppImage"
30 # create symbolic link
31 install -dm755 "${pkgdir}/usr/bin"
32 ln -s "${pkgdir}/opt/OXWU/oxwu.AppImage" "${pkgdir}/usr/bin/oxwu"
33 # Icon images
34 install -dm755 "${pkgdir}/usr/share/"
35 cp -a "${srcdir}/squashfs-root/usr/share/icons" "${pkgdir}/usr/share/"
36 install -Dm644 "${srcdir}/squashfs-root/oxwu.png" "${pkgdir}/opt/OXWU/oxwu.png"
37 install -Dm644 "${srcdir}/squashfs-root/oxwu.desktop" "${pkgdir}/usr/share/applications/oxwu.desktop"
38 install -Dm644 "${srcdir}/squashfs-root/oxwu.desktop" "${pkgdir}/etc/xdg/autostart/oxwu.desktop"
39}
40

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2
2026-09-12 00:25:17 Medium 2
2026-09-11 00:19:22 Medium 2
2026-09-10 00:22:44 Medium 2
2026-09-09 00:04:09 Medium 2
2026-09-08 00:18:08 Medium 2
2026-09-07 00:30:15 Medium 2
2026-09-06 00:17:06 Medium 2
2026-09-05 00:16:27 Medium 2
2026-09-04 00:03:13 Medium 2
2026-09-03 00:15:47 Medium 2
2026-09-02 00:02:31 Medium 2
2026-09-01 00:11:19 Medium 2
2026-08-31 00:19:57 Medium 2
2026-08-30 00:04:14 Medium 2
2026-08-29 00:29:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion