portal-mc-bin

MEDIUM
maintainer tiouo 0 votes scanned 2026-10-05 00:08:03.938595
View on AUR
Why flagged

The package downloads a prebuilt AppImage from GitHub (tiouoo/Portal), which is a legitimate source, but the maintainer is the same person who owns the domain (tiouo.cc), creating a potential conflict of interest; however, the AppImage comes from the project's official GitHub releases, reducing risk, though the SKIP'd checksum for the logo is harmless.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 "portal.png::https://portal.tiouo.cc/portal-logo.png"
Medium AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt AppImage from GitHub (tiouoo/Portal), which is a legitimate source, but the maintainer is the same person who owns the domain (tiouo.cc), creating a potential conflict of interest; however, the AppImage comes from the project's official GitHub releases, reducing risk, though the SKIP'd checksum for the logo is harmless.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: tiouoo <tiouo@qq.com>
2
3pkgname=portal-mc-bin
4pkgver=1.0.5
5pkgrel=1
6pkgdesc="Portal - Minecraft launcher/manager (stable release)"
7arch=('x86_64')
8url="https://portal.tiouo.cc/"
9license=('GPL-3.0-or-later')
10depends=('fuse2' 'hicolor-icon-theme' 'xdg-utils')
11provides=("portal-mc=$pkgver")
12conflicts=('portal-mc' 'portal-mc-commit-bin' 'portal-mc-nightly-bin')
13options=('!strip' '!emptydirs')
14_appimg="Portal.AppImage"
15source_x86_64=(
16 "$_appimg::https://github.com/tiouoo/Portal/releases/latest/download/Portal.linux.x64.AppImage"
17 "portal.png::https://portal.tiouo.cc/portal-logo.png"
18)
19sha256sums_x86_64=('d81bc432b1f966d54e5442951a7c38e7d381693b382d392e587a5e4cc74a5731' 'SKIP')
20noextract=("$_appimg")
21
22package() {
23 install -Dm755 "$srcdir/$_appimg" "$pkgdir/opt/portal/Portal.AppImage"
24 install -Dm755 /dev/stdin "$pkgdir/usr/bin/portal" <<'EOF'
25#!/bin/sh
26exec /opt/portal/Portal.AppImage "$@"
27EOF
28 install -Dm644 "$srcdir/portal.png" \
29 "$pkgdir/usr/share/icons/hicolor/512x512/apps/portal.png"
30 install -Dm644 /dev/stdin "$pkgdir/usr/share/applications/portal.desktop" <<'EOF'
31[Desktop Entry]
32Type=Application
33Name=Portal
34Comment=Portal - Minecraft launcher/manager
35Icon=portal
36Exec=portal %U
37Terminal=false
38Categories=Game;
39MimeType=x-scheme-handler/portal;application/zip;application/x-zip-compressed;
40EOF
41}
42

Scan history

Scanned at (UTC)SeverityRules
2026-10-05 00:08:03 Medium 2
2026-10-04 00:18:08 Medium 2
2026-10-03 00:23:04 Medium 2
2026-10-02 00:00:32 Medium 2
2026-10-01 00:02:06 Medium 2
2026-09-30 00:20:07 Medium 2
2026-09-29 00:07:46 Medium 2
2026-09-28 00:28:32 Medium 2
2026-09-27 00:07:07 Medium 2
2026-09-26 00:12:15 Medium 2
2026-09-25 00:03:36 Medium 2
2026-09-24 00:24:14 Medium 2
2026-09-23 00:28:13 Medium 2
2026-09-22 00:15:14 Medium 2
2026-09-21 00:26:32 Medium 2
2026-09-20 00:25:31 Medium 2
2026-09-19 00:25:36 Medium 2
2026-09-18 00:17:11 Medium 2
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion