purrr-client-bin

MEDIUM
maintainer MeIsGaming 0 votes scanned 2026-09-28 15:23:57.397714
View on AUR
Why flagged

A prebuilt binary .deb is downloaded from a self-hosted Forgejo instance (git.purrr.chat) belonging to the maintainer, not an established official vendor infrastructure; the binary is extracted and installed directly without any verification beyond a single SHA256 checksum, making it a swappable prebuilt from a personal/project-owned but unverifiable host — acceptable risk level for a medium rating.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source=("${_pkgname}-${pkgver}.deb::https://git.purrr.chat/ashley/purrr-client/releases/download/v${pkgver}/${_pkgname}_${pkgver}_amd64.deb")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): A prebuilt binary .deb is downloaded from a self-hosted Forgejo instance (git.purrr.chat) belonging to the maintainer, not an established official vendor infrastructure; the binary is extracted and installed directly without any verification beyond a single SHA256 checksum, making it a swappable prebuilt from a personal/project-owned but unverifiable host — acceptable risk level for a medium rating.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Ashley Piller <ashley@purrr.chat>
2# Prebuilt native desktop client for purrr. Ships the fertigen Binary aus dem
3# Forgejo-Release — kein lokaler Build, kein offener Quellcode nötig.
4pkgname=purrr-client-bin
5_pkgname=purrr
6pkgver=0.1.6
7pkgrel=1
8pkgdesc="Native desktop client for purrr, a cozy self-hosted Discord alternative (prebuilt binary)"
9arch=('x86_64')
10url="https://purrr.chat"
11license=('AGPL-3.0-or-later')
12depends=('webkit2gtk-4.1' 'gtk3' 'libayatana-appindicator')
13provides=('purrr-client')
14conflicts=('purrr-client' 'purrr-client-git')
15options=('!strip' '!debug')
16# The .deb Tauri produces already carries the binary, .desktop entry and icons.
17source=("${_pkgname}-${pkgver}.deb::https://git.purrr.chat/ashley/purrr-client/releases/download/v${pkgver}/${_pkgname}_${pkgver}_amd64.deb")
18noextract=("${_pkgname}-${pkgver}.deb")
19# TODO: replace with the real hash once the first release is cut (updpkgsums).
20sha256sums=('811483b60ed2918d9ce1ce1fa3145bb990fa642ab31f6193b69cab6f0b32a703')
21
22package() {
23 # A .deb is an `ar` archive; bsdtar (libarchive) reads it directly.
24 bsdtar -xf "${srcdir}/${_pkgname}-${pkgver}.deb" -C "${srcdir}"
25 # The payload (binary, .desktop entry, icons) lives in data.tar.*.
26 bsdtar -xf "${srcdir}"/data.tar.* -C "${pkgdir}"
27}
28

Scan history

Scanned at (UTC)SeverityRules
2026-09-28 15:23:57 Medium 3
2026-09-28 15:21:17 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion