sfptool-bin

maintainer jonasled · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt x86_64 binary (.deb) from a personal S3 bucket (s3.jonasled.de) rather than an official distribution channel or the project's own GitHub releases. The binary is extracted and installed directly without any additional verification beyond the sha256sum. While the sha256sum provides integrity checking against accidental corruption or simple substitution, the host is a personal S3 bucket controlled by the maintainer — if that bucket were compromised or the object replaced, the sha256sum in the PKGBUILD would no longer match and the build would fail, which is a meaningful protection. However, the source is still a prebuilt binary from a non-official/non-auditable host (not a distro mirror, not a GitHub release artifact from the canonical repo), which is a genuine supply-chain concern: users are trusting the maintainer's S3 bucket to serve the correct binary. The project URL points to a Gitea instance (jonasled.dev) which is also personal infrastructure. This is a classic AUR binary package pattern that carries real but not catastrophic supply-chain risk — medium severity is appropriate.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("sfp-tool_1.4.2_amd64.deb::https://s3.jonasled.de/sfp-tool/linux/x86_64/sfp-tool_1.4.2_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt x86_64 binary (.deb) from a personal S3 bucket (s3.jonasled.de) rather than an official distribution channel or the project's own GitHub releases. The binary is extracted and installed directly without any additional verification beyond the sha256sum. While the sha256sum provides integrity checking against accidental corruption or simple substitution, the host is a personal S3 bucket controlled by the maintainer — if that bucket were compromised or the object replaced, the sha256sum in the PKGBUILD would no longer match and the build would fail, which is a meaningful protection. However, the source is still a prebuilt binary from a non-official/non-auditable host (not a distro mirror, not a GitHub release artifact from the canonical repo), which is a genuine supply-chain concern: users are trusting the maintainer's S3 bucket to serve the correct binary. The project URL points to a Gitea instance (jonasled.dev) which is also personal infrastructure. This is a classic AUR binary package pattern that carries real but not catastrophic supply-chain risk — medium severity is appropriate.

PKGBUILD

1 offending line(s) highlighted
1pkgname=sfptool-bin
2pkgver=1.4.2
3pkgrel=1
4pkgdesc="Desktop utility for reading and programming SFP and QSFP transceivers"
5arch=('x86_64')
6url="https://jonasled.dev/jonasled/sfp-tool"
7license=('GPL3')
8depends=('gtk3' 'webkit2gtk-4.1' 'libayatana-appindicator')
9makedeps=('binutils')
10provides=('sfptool')
11conflicts=('sfptool')
12source=("sfp-tool_1.4.2_amd64.deb::https://s3.jonasled.de/sfp-tool/linux/x86_64/sfp-tool_1.4.2_amd64.deb")
13sha256sums=('7c99ffb96b3b4f310177342c67fd97799719681eece8772b84a6838991106b3d')
14
15package() {
16 cd "$srcdir"
17 local data_archive
18 ar x "sfp-tool_1.4.2_amd64.deb"
19 tar -xvf data.tar.* -C "$pkgdir/"
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion