rosu-patcher-bin

MEDIUM
maintainer Lecer 0 votes scanned 2026-10-07 14:14:59.268871
View on AUR
Why flagged

A prebuilt binary is downloaded from a non-official personal/project server (ussr.pl) with a SKIP'd checksum, meaning the binary is unverifiable and could be silently swapped at any time; while ussr.pl appears to be the RealistikOsu project's own domain, the lack of any checksum or versioned/pinned URL makes this a supply-chain risk for an executable that runs directly on the user's system.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:21 source=("rosu-patcher-$pkgver::https://ussr.pl/api/v1/patcher/launcher/linux/download")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 80%): A prebuilt binary is downloaded from a non-official personal/project server (ussr.pl) with a SKIP'd checksum, meaning the binary is unverifiable and could be silently swapped at any time; while ussr.pl appears to be the RealistikOsu project's own domain, the lack of any checksum or versioned/pinned URL makes this a supply-chain risk for an executable that runs directly on the user's system.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Aochi <me@aochi.uk>
2pkgname=rosu-patcher-bin
3pkgver=20261007.1
4pkgrel=1
5pkgdesc="Launcher for the RealistikOsu Patcher"
6arch=('x86_64')
7url="https://ussr.pl"
8license=('LicenseRef-proprietary')
9depends=('glibc' 'libx11' 'libice' 'libsm' 'fontconfig' 'openssl' 'zlib')
10optdepends=(
11 'osu-winello: run osu! stable through Wine'
12 'osu-lazer-bin: run osu!lazer'
13 'gst-plugins-base: intro video'
14 'gst-libav: intro video codecs'
15)
16provides=('rosu-patcher')
17conflicts=('rosu-patcher')
18options=('!strip')
19# The binary comes from the patcher backend, which serves whatever version is current, so this checksum has to be
20# updated with every release (or pointed at a versioned GitHub release once there is one).
21source=("rosu-patcher-$pkgver::https://ussr.pl/api/v1/patcher/launcher/linux/download")
22sha256sums=('SKIP')
23
24package() {
25 install -Dm755 "$srcdir/rosu-patcher-$pkgver" "$pkgdir/usr/bin/rosu-patcher"
26}
27

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 14:14:59 Medium 3
2026-10-07 14:05:47 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion