querypie

maintainer orphaned · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt AppImage binary from a CloudFront CDN URL (d2f8621kw7pn7s.cloudfront.net) that is not the official vendor's primary domain (querypie.com). The AppImage is then extracted and installed as a full application under /opt. While a sha256sum is provided (providing some integrity check), the source is a CDN distribution endpoint rather than a verifiable official release host like GitHub releases or the vendor's own domain. The binary is executed during build (--appimage-extract) and installed as a runnable application. This is a genuine medium-severity supply-chain concern: if the CDN bucket were compromised or the URL redirected, malicious code would be installed. The sha256sum mitigates but does not eliminate the risk since it only verifies the current pinned version and could be updated alongside a compromised binary in a future PKGBUILD revision.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("${pkgname}-${pkgver}.AppImage::https://d2f8621kw7pn7s.cloudfront.net/latest/QueryPie-${pkgver}.AppImage?v=${pkgver}-latest.200615184"
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 75%): The PKGBUILD downloads a prebuilt AppImage binary from a CloudFront CDN URL (d2f8621kw7pn7s.cloudfront.net) that is not the official vendor's primary domain (querypie.com). The AppImage is then extracted and installed as a full application under /opt. While a sha256sum is provided (providing some integrity check), the source is a CDN distribution endpoint rather than a verifiable official release host like GitHub releases or the vendor's own domain. The binary is executed during build (--appimage-extract) and installed as a runnable application. This is a genuine medium-severity supply-chain concern: if the CDN bucket were compromised or the URL redirected, malicious code would be installed. The sha256sum mitigates but does not eliminate the risk since it only verifies the current pinned version and could be updated alongside a compromised binary in a future PKGBUILD revision.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Dimitris Kiziridis <ragouel at outlook dot com>
2
3pkgname=querypie
4pkgver=6.2.0
5pkgrel=1
6pkgdesc="The most advanced Data Warehouse Client for data analytics teams.
7Optimized for Snowflake, Presto, BigQuery, and Redshift"
8arch=('x86_64')
9url='https://www.querypie.com'
10license=("custom:${pkgname}")
11makedepends=('gendesk')
12noextract=("${pkgname}-${pkgver}.AppImage")
13source=("${pkgname}-${pkgver}.AppImage::https://d2f8621kw7pn7s.cloudfront.net/latest/QueryPie-${pkgver}.AppImage?v=${pkgver}-latest.200615184"
14 'LICENSE')
15sha256sums=('8ece78588dc1604cf052c3962b664c8400bdb7516d9a6158d043e532d10a7da1'
16 'SKIP')
17
18package() {
19 chmod 755 ./${pkgname}-${pkgver}.AppImage
20 ./${pkgname}-${pkgver}.AppImage --appimage-extract
21 install -Dm644 squashfs-root/usr/share/icons/hicolor/256x256/apps/querypie.png "${pkgdir}/usr/share/pixmaps/querypie.png"
22 gendesk -f -n --pkgname "${pkgname}" \
23 --pkgdesc "$pkgdesc" \
24 --name "QueryPie" \
25 --comment "$pkgdesc" \
26 --exec "${pkgname}" \
27 --categories 'Utility;Development;Application' \
28 --icon "${pkgname}" \
29 --mimetypes=x-scheme-handler/querypie; \
30 install -Dm644 "${pkgname}.desktop" -t "${pkgdir}/usr/share/applications"
31 install -d "${pkgdir}/usr/bin"
32 install -d "${pkgdir}/opt"
33 cp -avR squashfs-root/ "${pkgdir}/opt/${pkgname}"
34 ln -s /opt/${pkgname}/AppRun "${pkgdir}/usr/bin/${pkgname}"
35 find "${pkgdir}/opt/${pkgname}" -type d -exec chmod 755 {} +
36 install -Dm644 LICENSE -t "${pkgdir}/usr/share/licenses/${pkgname}"
37}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion