proton-pass-bin
The package downloads a prebuilt .deb binary from a non-whitelisted host (proton.me), which is not a standard source for AUR packages; while proton.me is the official project domain, the lack of verifiable build process and use of a binary blob creates a supply-chain risk if the host were compromised.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
source=("https://proton.me/download/PassDesktop/linux/x64/proton-pass_${pkgver}_amd64.deb")
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt .deb binary from a non-whitelisted host (proton.me), which is not a standard source for AUR packages; while proton.me is the official project domain, the lack of verifiable build process and use of a binary blob creates a supply-chain risk if the host were compromised.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Echo J. <aidas957 at gmail dot com>
# Contributor: Mysti
pkgname=proton-pass-bin
pkgver=1.40.0
pkgrel=1
pkgdesc="Open-source password manager for effortless protection. Securely store, share and auto-login your accounts with Proton Pass, using end-to-end encryption trusted by millions."
arch=("x86_64")
url="https://proton.me/pass"
license=('MIT') # Bundled Electron
license+=('GPL-3.0-or-later') # The Proton Pass code itself (https://github.com/ProtonMail/WebClients#license)
groups=("ProtonPass")
depends=('alsa-lib' 'at-spi2-core' 'cairo' 'dbus' 'expat' 'glib2' 'glibc' 'gtk3' 'libcups'
'libgcc' 'libudev.so' 'libx11' 'libxcb' 'libxcomposite' 'libxdamage' 'libxext'
'libxfixes' 'libxrandr' 'libxkbcommon' 'mesa' 'nspr' 'nss' 'pango') # Bundled Electron dependencies
provides=('proton-pass' 'protonpass')
conflicts=('proton-pass' 'protonpass')
source=("https://proton.me/download/PassDesktop/linux/x64/proton-pass_${pkgver}_amd64.deb")
sha512sums=('4f1be04f38cee1f858b4901269d697a4ad78d967425596b743f2fded8f095f5951b4a0d2620324175705dca07b77cca63e78837f53e846fae3c98a426a1c78b5')
package() {
tar -xvf data.tar.xz -C "$pkgdir/"
install -dm755 "$pkgdir"/opt
mv "$pkgdir"/usr/lib/proton-pass "$pkgdir"/opt
rmdir "$pkgdir"/usr/lib
ln -sf "/opt/proton-pass/Proton Pass" "$pkgdir"/usr/bin/proton-pass
# Remove world-writable bit from some files
chmod -R o-w "$pkgdir"/opt/proton-pass/resources/assets
# Install bundled Electron license
install -Dm644 "$pkgdir"/usr/share/doc/proton-pass/copyright "$pkgdir"/usr/share/licenses/"$pkgname"/copyright
rm -rf "$pkgdir"/usr/share/{doc,lintian}
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Medium | 2 |
| 2026-10-01 00:02:06 | Medium | 2 |
| 2026-09-30 00:20:07 | Medium | 2 |
| 2026-09-29 00:07:46 | Medium | 2 |
| 2026-09-28 00:28:32 | Medium | 2 |
| 2026-09-27 00:07:07 | Medium | 2 |
| 2026-09-26 00:12:15 | Medium | 2 |
| 2026-09-25 00:03:36 | Medium | 2 |
| 2026-09-24 00:24:14 | Medium | 2 |
| 2026-09-23 00:28:13 | Medium | 2 |
| 2026-09-22 00:15:14 | Medium | 2 |
| 2026-09-21 00:26:32 | Medium | 2 |
| 2026-09-20 00:25:31 | Medium | 2 |
| 2026-09-19 00:25:36 | Medium | 2 |
| 2026-09-18 00:17:11 | Medium | 2 |
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |