setl

maintainer keenerd · 2 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads and installs prebuilt binaries (setl, setlcpp, setltran) directly from setl.org, which is the official upstream project website for the SETL language. The binaries are verified only with MD5 (weak, but present). The concern is real but moderate: these are executed binaries from a non-PyPI/non-GitHub host, and setl.org is a small, potentially unmaintained project site. However, setl.org is the canonical upstream URL (matching the pkgurl field), not a personal or third-party mirror, so this is more analogous to a vendor distributing their own binaries than a supply-chain substitution. The use of HTTP (not HTTPS) is a genuine downgrade concern allowing MITM, and MD5 is cryptographically weak. Overall this is a legitimate medium: prebuilt binaries from a small upstream host over plain HTTP with only MD5 verification, but not clearly malicious.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("http://setl.org/setl/bin/Linux-x86-32bit/setlbin.tgz")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads and installs prebuilt binaries (setl, setlcpp, setltran) directly from setl.org, which is the official upstream project website for the SETL language. The binaries are verified only with MD5 (weak, but present). The concern is real but moderate: these are executed binaries from a non-PyPI/non-GitHub host, and setl.org is a small, potentially unmaintained project site. However, setl.org is the canonical upstream URL (matching the pkgurl field), not a personal or third-party mirror, so this is more analogous to a vendor distributing their own binaries than a supply-chain substitution. The use of HTTP (not HTTPS) is a genuine downgrade concern allowing MITM, and MD5 is cryptographically weak. Overall this is a legitimate medium: prebuilt binaries from a small upstream host over plain HTTP with only MD5 verification, but not clearly malicious.

PKGBUILD

1 offending line(s) highlighted
1# Contributor: Kyle Keen <keenerd@gmail.com>
2pkgname=setl
3pkgver=0.1.2
4pkgrel=1
5pkgdesc="High level dynamic set based language."
6arch=('i686' 'x86_64')
7url="http://setl.org/setl/"
8license=('GPL')
9depends=('glibc')
10
11case $CARCH in
12 'i686')
13 source=("http://setl.org/setl/bin/Linux-x86-32bit/setlbin.tgz")
14 md5sums=('584da279b18496655057fe72a085982a')
15 ;;
16 'x86_64')
17 source=("http://setl.org/setl/bin/Linux-x86-64bit/setlbin.tgz")
18 md5sums=('74ed85446def1975dcb36a7d3cbcf00b')
19 ;;
20esac
21
22package() {
23 cd "$srcdir"
24 install -d "$pkgdir/usr/bin"
25 install -m755 setl{,cpp,tran} "$pkgdir/usr/bin/"
26}
27
28
29

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion