querypie
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("${pkgname}-${pkgver}.AppImage::https://d2f8621kw7pn7s.cloudfront.net/latest/QueryPie-${pkgver}.AppImage?v=${pkgver}-latest.200615184"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 75%): The PKGBUILD downloads a prebuilt AppImage binary from a CloudFront CDN URL (d2f8621kw7pn7s.cloudfront.net) that is not the official vendor's primary domain (querypie.com). The AppImage is then extracted and installed as a full application under /opt. While a sha256sum is provided (providing some integrity check), the source is a CDN distribution endpoint rather than a verifiable official release host like GitHub releases or the vendor's own domain. The binary is executed during build (--appimage-extract) and installed as a runnable application. This is a genuine medium-severity supply-chain concern: if the CDN bucket were compromised or the URL redirected, malicious code would be installed. The sha256sum mitigates but does not eliminate the risk since it only verifies the current pinned version and could be updated alongside a compromised binary in a future PKGBUILD revision.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Dimitris Kiziridis <ragouel at outlook dot com>
pkgname=querypie
pkgver=6.2.0
pkgrel=1
pkgdesc="The most advanced Data Warehouse Client for data analytics teams.
Optimized for Snowflake, Presto, BigQuery, and Redshift"
arch=('x86_64')
url='https://www.querypie.com'
license=("custom:${pkgname}")
makedepends=('gendesk')
noextract=("${pkgname}-${pkgver}.AppImage")
source=("${pkgname}-${pkgver}.AppImage::https://d2f8621kw7pn7s.cloudfront.net/latest/QueryPie-${pkgver}.AppImage?v=${pkgver}-latest.200615184"
'LICENSE')
sha256sums=('8ece78588dc1604cf052c3962b664c8400bdb7516d9a6158d043e532d10a7da1'
'SKIP')
package() {
chmod 755 ./${pkgname}-${pkgver}.AppImage
./${pkgname}-${pkgver}.AppImage --appimage-extract
install -Dm644 squashfs-root/usr/share/icons/hicolor/256x256/apps/querypie.png "${pkgdir}/usr/share/pixmaps/querypie.png"
gendesk -f -n --pkgname "${pkgname}" \
--pkgdesc "$pkgdesc" \
--name "QueryPie" \
--comment "$pkgdesc" \
--exec "${pkgname}" \
--categories 'Utility;Development;Application' \
--icon "${pkgname}" \
--mimetypes=x-scheme-handler/querypie; \
install -Dm644 "${pkgname}.desktop" -t "${pkgdir}/usr/share/applications"
install -d "${pkgdir}/usr/bin"
install -d "${pkgdir}/opt"
cp -avR squashfs-root/ "${pkgdir}/opt/${pkgname}"
ln -s /opt/${pkgname}/AppRun "${pkgdir}/usr/bin/${pkgname}"
find "${pkgdir}/opt/${pkgname}" -type d -exec chmod 755 {} +
install -Dm644 LICENSE -t "${pkgdir}/usr/share/licenses/${pkgname}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |