pymoldyn-bin
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("http://pgi-jcns.fz-juelich.de/pub/downloads/software/pymoldyn_${pkgver}-1_amd64.deb")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 78%): The PKGBUILD downloads a prebuilt x86_64 binary .deb from pgi-jcns.fz-juelich.de, which is the Forschungszentrum Jülich (FZJ) Peter Grünberg Institute computing center — a legitimate German research institution and the actual upstream developer of pyMolDyn (the GitHub repo sciapp/pyMolDyn is also associated with FZJ/PGI). This is not a random personal host; it is the official institutional distribution server for this software. A sha256sum is present and pinned. However, the package still installs a prebuilt binary blob directly without building from source, and the host is not a major well-known package mirror. The risk is real but low in practice: if the binary at that URL were replaced, the sha256 check would catch it. The main residual concern is that the sha256 is only as trustworthy as whoever submitted the PKGBUILD, and there is no GPG signature verification. Overall this is a standard 'binary repackage from upstream institutional host with checksum' pattern — medium by strict supply-chain standards but not a genuine attack.
PKGBUILD
1 offending line(s) highlightedpkgname="pymoldyn-bin"
pkgver="0.9.9"
pkgrel="4"
pkgdesc="A molecule viewer with cavity computation."
arch=("x86_64")
url="https://github.com/sciapp/pyMolDyn"
license=("MIT")
depends=()
makedepends=()
provides=("${pkgname%-*}=${pkgver}")
conflicts=("${pkgname%-*}")
source=("http://pgi-jcns.fz-juelich.de/pub/downloads/software/pymoldyn_${pkgver}-1_amd64.deb")
sha256sums=("11eecd3d0c35aaa1d71a61519e0de5fc7b4e2b0a8d290cecc819b969426b2d4f")
package() {
cd "${srcdir}" && \
tar -xzf data.tar.gz --no-same-owner -C "${pkgdir}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |