spinnaker-spin

maintainer Alberto_OS · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary from storage.googleapis.com/spinnaker-artifacts, which is the official Spinnaker project's artifact storage bucket on Google Cloud Storage. This is the canonical distribution channel used by the Spinnaker project itself (documented at spinnaker.io). However, it is still a prebuilt binary with no source compilation, and GCS buckets can be misconfigured or taken over. The sha256sum provides integrity verification against tampering in transit, but does not protect against the upstream artifact itself being replaced at the source. This is a legitimate medium-risk pattern: an executed binary from what appears to be the official vendor host, but without source compilation. The risk is real but not elevated — this matches the standard medium classification for prebuilt binary packages.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=("https://storage.googleapis.com/spinnaker-artifacts/spin/$pkgver/linux/amd64/spin")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt binary from storage.googleapis.com/spinnaker-artifacts, which is the official Spinnaker project's artifact storage bucket on Google Cloud Storage. This is the canonical distribution channel used by the Spinnaker project itself (documented at spinnaker.io). However, it is still a prebuilt binary with no source compilation, and GCS buckets can be misconfigured or taken over. The sha256sum provides integrity verification against tampering in transit, but does not protect against the upstream artifact itself being replaced at the source. This is a legitimate medium-risk pattern: an executed binary from what appears to be the official vendor host, but without source compilation. The risk is real but not elevated — this matches the standard medium classification for prebuilt binary packages.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Alberto Oliveira <orkan.aos@gmail.com>
2pkgname=spinnaker-spin
3pkgver=1.30.0
4pkgrel=1
5pkgdesc="Spin is a command-line administration tool to manage Spinnaker applications, pipelines and configs"
6arch=('x86_64')
7url="https://spinnaker.io/docs/guides/spin/"
8license=('Apache')
9provides=('spin=$pkgver')
10source=("https://storage.googleapis.com/spinnaker-artifacts/spin/$pkgver/linux/amd64/spin")
11sha256sums=('1745a658a03887d896cd439b7f209ce3255d428998ca34d52be1e8d3565d6b01')
12
13package() {
14 install -Dm 755 "$srcdir/spin" "$pkgdir/usr/bin/spin"
15}
16

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion