pocketnes

maintainer Sterophonick · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The package downloads a ZIP archive containing Windows executables (apack.exe, nespack7.exe, pnesmmw.exe, pocketnes.gba) from dwedit.org, a personal/unofficial host. These binaries are installed and executed via Wine. dwedit.org is actually the personal site of the known GBA homebrew developer 'dwedit' who created PocketNES, so this is the de-facto upstream source rather than a random third-party mirror. However, it remains a personal host with no code-signing or reproducible build verification, and the md5sums only cover the ZIP (not the individual executables within it). The wrapper script and desktop file are sourced locally with SKIP checksums. The core concern is that prebuilt Windows binaries from a personal website are being installed and run via Wine — a genuine supply-chain risk if the host were compromised, but not an active attack. This fits the medium category: executed binaries from an unofficial/personal host.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=(https://www.dwedit.org/gba/pocketnes_2013_07_01.zip
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The package downloads a ZIP archive containing Windows executables (apack.exe, nespack7.exe, pnesmmw.exe, pocketnes.gba) from dwedit.org, a personal/unofficial host. These binaries are installed and executed via Wine. dwedit.org is actually the personal site of the known GBA homebrew developer 'dwedit' who created PocketNES, so this is the de-facto upstream source rather than a random third-party mirror. However, it remains a personal host with no code-signing or reproducible build verification, and the md5sums only cover the ZIP (not the individual executables within it). The wrapper script and desktop file are sourced locally with SKIP checksums. The core concern is that prebuilt Windows binaries from a personal website are being installed and run via Wine — a genuine supply-chain risk if the host were compromised, but not an active attack. This fits the medium category: executed binaries from an unofficial/personal host.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Sterophonick
2pkgname=pocketnes
3_pkgname='pocketnes'
4pkgver=1.2a
5pkgrel=1
6pkgdesc='PocketNES ROM Builder'
7arch=(x86_64 i686)
8depends=('wine' 'winetricks')
9source=(https://www.dwedit.org/gba/pocketnes_2013_07_01.zip
10 pocketnes
11 pocketnes.desktop
12 pocketnes.png)
13md5sums=('2bc7fbfaf80eeadfc5b6145d370db800'
14 'SKIP'
15 'SKIP'
16 'SKIP')
17options=(!debug !strip)
18
19package() {
20 install -Dm755 pocketnes $pkgdir/usr/bin/pocketnes
21 install -Dm644 pocketnes.desktop $pkgdir/usr/share/applications/pocketnes.desktop
22 install -Dm644 pocketnes.png $pkgdir/usr/share/pixmaps/pocketnes.png
23
24 mkdir -p $pkgdir/usr/share/pocketnes
25
26 cp -r $srcdir/apack.exe $pkgdir/usr/share/pocketnes
27 cp -r $srcdir/menumaker.txt $pkgdir/usr/share/pocketnes
28 cp -r $srcdir/nespack7.exe $pkgdir/usr/share/pocketnes
29 cp -r $srcdir/pnesmmw.exe $pkgdir/usr/share/pocketnes
30 cp -r $srcdir/pnesmmw.mdb $pkgdir/usr/share/pocketnes
31 cp -r $srcdir/pocketnes.gba $pkgdir/usr/share/pocketnes
32 chmod -R 777 $pkgdir/usr/share/pocketnes
33}
34

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion