pymoldyn-bin

maintainer IngoMeyer · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt x86_64 binary .deb from pgi-jcns.fz-juelich.de, which is the Forschungszentrum Jülich (FZJ) Peter Grünberg Institute computing center — a legitimate German research institution and the actual upstream developer of pyMolDyn (the GitHub repo sciapp/pyMolDyn is also associated with FZJ/PGI). This is not a random personal host; it is the official institutional distribution server for this software. A sha256sum is present and pinned. However, the package still installs a prebuilt binary blob directly without building from source, and the host is not a major well-known package mirror. The risk is real but low in practice: if the binary at that URL were replaced, the sha256 check would catch it. The main residual concern is that the sha256 is only as trustworthy as whoever submitted the PKGBUILD, and there is no GPG signature verification. Overall this is a standard 'binary repackage from upstream institutional host with checksum' pattern — medium by strict supply-chain standards but not a genuine attack.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("http://pgi-jcns.fz-juelich.de/pub/downloads/software/pymoldyn_${pkgver}-1_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 78%): The PKGBUILD downloads a prebuilt x86_64 binary .deb from pgi-jcns.fz-juelich.de, which is the Forschungszentrum Jülich (FZJ) Peter Grünberg Institute computing center — a legitimate German research institution and the actual upstream developer of pyMolDyn (the GitHub repo sciapp/pyMolDyn is also associated with FZJ/PGI). This is not a random personal host; it is the official institutional distribution server for this software. A sha256sum is present and pinned. However, the package still installs a prebuilt binary blob directly without building from source, and the host is not a major well-known package mirror. The risk is real but low in practice: if the binary at that URL were replaced, the sha256 check would catch it. The main residual concern is that the sha256 is only as trustworthy as whoever submitted the PKGBUILD, and there is no GPG signature verification. Overall this is a standard 'binary repackage from upstream institutional host with checksum' pattern — medium by strict supply-chain standards but not a genuine attack.

PKGBUILD

1 offending line(s) highlighted
1pkgname="pymoldyn-bin"
2pkgver="0.9.9"
3pkgrel="4"
4pkgdesc="A molecule viewer with cavity computation."
5arch=("x86_64")
6url="https://github.com/sciapp/pyMolDyn"
7license=("MIT")
8depends=()
9makedepends=()
10provides=("${pkgname%-*}=${pkgver}")
11conflicts=("${pkgname%-*}")
12source=("http://pgi-jcns.fz-juelich.de/pub/downloads/software/pymoldyn_${pkgver}-1_amd64.deb")
13sha256sums=("11eecd3d0c35aaa1d71a61519e0de5fc7b4e2b0a8d290cecc819b969426b2d4f")
14
15package() {
16 cd "${srcdir}" && \
17 tar -xzf data.tar.gz --no-same-owner -C "${pkgdir}"
18}
19

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion