space_dapp

maintainer orphaned · 2 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged A single C source file is downloaded from darkshed.net, a personal/unofficial host with no clear affiliation to the project's stated homepage (tenr.de). The file is compiled and installed as an executable binary. While an md5sum is present (though md5 is weak), the supply-chain risk is real: if darkshed.net is compromised or the file is substituted, arbitrary C code would be compiled and installed as a setuid-capable binary in /usr/bin. The source host is neither the project's own domain nor a recognized ecosystem mirror. This is a genuine medium-severity supply-chain concern — executed compiled code from an unofficial third-party host.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=(http://darkshed.net/files/c_cpp/bits/$pkgname.c)
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): A single C source file is downloaded from darkshed.net, a personal/unofficial host with no clear affiliation to the project's stated homepage (tenr.de). The file is compiled and installed as an executable binary. While an md5sum is present (though md5 is weak), the supply-chain risk is real: if darkshed.net is compromised or the file is substituted, arbitrary C code would be compiled and installed as a setuid-capable binary in /usr/bin. The source host is neither the project's own domain nor a recognized ecosystem mirror. This is a genuine medium-severity supply-chain concern — executed compiled code from an unofficial third-party host.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Brian Bidulock <bidulock@openss7.org>
2# Contributor: sh0 <mee@sh0.org>
3pkgname=space_dapp
4pkgver=0.0.1
5pkgrel=4
6pkgdesc="A spacer dockapp"
7url="http://tenr.de/howto/space_dapp/space_dapp.html"
8arch=('i686' 'x86_64')
9license=('MIT')
10depends=('libx11' 'libxext' 'libxcb' 'libxau' 'libxdmcp')
11source=(http://darkshed.net/files/c_cpp/bits/$pkgname.c)
12md5sums=('187b12a1f68fcfe13442d9a65261230d')
13
14build() {
15 cd $srcdir
16 gcc -o space_dapp space_dapp.c -DSHAPE -I/usr/include/X11/ -lX11 -lXext
17}
18package() {
19 cd $srcdir
20 install -D -m755 space_dapp $pkgdir/usr/bin/space_dapp
21}
22

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion