spotify
MEDIUM
maintainer gromit
276 votes
scanned 2026-10-02 00:00:32.890515
Why flagged
Downloads a prebuilt Debian package from a non-whitelisted but official Spotify domain, which is an unverifiable executable with supply-chain risk despite domain legitimacy.
Triggered rules
Medium
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:29
source=("${pkgname}-${pkgver}-${_commit}-x86_64.deb::http://repository.spotify.com/pool/non-free/s/spotify-client/spotify-client_${pkgver}.${_commit}_amd64.deb"
Medium
AI review of an ambiguous pattern
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 90%): Downloads a prebuilt Debian package from a non-whitelisted but official Spotify domain, which is an unverifiable executable with supply-chain risk despite domain legitimacy.
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Christian Heusel <christian@heusel.eu>
2
# Maintainer: Robin Candau <antiz@archlinux.org>
3
# Contributor: NicoHood <archlinux {cat} nicohood {dog} de>
4
# Contributor: TobFromme < TobFromme {hat} pm {dont} me >
5
# Contributor: Ashley Whetter <(firstname) @ awhetter.co.uk>
6
# Contributor: Eothred <yngve.levinsen@gmail.com>
7
8
pkgname=spotify
9
pkgver='1.2.96.518'
10
epoch=1
11
_commit=g366879e1
12
pkgrel=2
13
pkgdesc='A proprietary music streaming service'
14
arch=('x86_64')
15
license=('custom')
16
url='https://www.spotify.com'
17
depends=('alsa-lib>=1.0.14' 'gtk3' 'libxss' 'desktop-file-utils' 'openssl' 'nss' 'at-spi2-atk' 'libcurl-gnutls' 'libsm' 'libayatana-appindicator' 'libayatana-indicator')
18
optdepends=('ffmpeg4.4: Adds support for playback of local files'
19
'zenity: Adds support for importing local files'
20
'libnotify: Desktop notifications')
21
options=('!strip')
22
23
# NOTE: We switched from stable to testing on 18th march, as the spotify
24
# stable repository is always outdated. Testing seems to be in sync with snap:
25
# https://snapcraft.io/spotify
26
# http://repository.spotify.com/dists/testing/Release
27
# http://repository.spotify.com/dists/testing/non-free/binary-amd64/Packages
28
# http://repository.spotify.com/dists/testing/Release.gpg
29
source=("${pkgname}-${pkgver}-${_commit}-x86_64.deb::http://repository.spotify.com/pool/non-free/s/spotify-client/spotify-client_${pkgver}.${_commit}_amd64.deb"
30
"spotify.sh"
31
"spotify.protocol"
32
"LICENSE"
33
# GPG signature check
34
"${pkgname}-${pkgver}-${pkgrel}-Release::http://repository.spotify.com/dists/testing/Release"
35
"${pkgname}-${pkgver}-${pkgrel}-Release.sig::http://repository.spotify.com/dists/testing/Release.gpg"
36
"${pkgname}-${pkgver}-${pkgrel}-x86_64-Packages::http://repository.spotify.com/dists/testing/non-free/binary-amd64/Packages")
37
sha512sums=('98d25bd748258ca8b8357313cd35c7188bb0b26ed2d4390b0208473aa9fa3491a095559762f8ba06ec0828d73e05ee8fb488f0f357340191da4c65dd1f93c519'
38
'da48b628a4ea925dd8521133ebf364b261b11aed252d264dde6605d915cdb631919ffe672c58534bcdb60869e5d87a49a60a8198780b99517123f0031e83fdb1'
39
'999abe46766a4101e27477f5c9f69394a4bb5c097e2e048ec2c6cb93dfa1743eb436bde3768af6ba1b90eaac78ea8589d82e621f9cbe7d9ab3f41acee6e8ca20'
40
'2e16f7c7b09e9ecefaa11ab38eb7a792c62ae6f33d95ab1ff46d68995316324d8c5287b0d9ce142d1cf15158e61f594e930260abb8155467af8bc25779960615'
41
'18f27971697835df865d63465d86d1250b20b9d1c12bbf7df1eafeef5c66bf0b3134c25b08269f72d4b7a4287151336ee3fd0f70bc46da25f13e8c91c004f710'
42
'SKIP'
43
'1fbb6f1f104b998265faafeb62cb3aff6d7048b2e689292049fbbe867ea4071af3b73fc5a023bff8d4c1e579e5d904c78179e3650ae4740602583db8e13bde8a')
44
45
# Import key with:
46
# curl -sS https://download.spotify.com/debian/pubkey_5384CE82BA52C83A.gpg | gpg --import -
47
validpgpkeys=('E1096BCBFF6D418796DE78515384CE82BA52C83A') # Spotify Public Repository Signing Key <tux@spotify.com>
48
# Old Keys:
49
# 63CBEEC9006602088F9B19326224F9941A8AA6D1
50
# E27409F51D1B66337F2D2F417A3A762FAFD4A51F
51
# F9A211976ED662F00E59361E5E3C45D7B312C643
52
# 8FD3D9A8D3800305A9FFF259D1742AD60D811D58
53
# 931FF8E79F0876134EDDBDCCA87FF9DF48BF1C90
54
# 2EBF997C15BDA244B6EBF5D84773BD5E130D1D45
55
# B420FD3777CCE3A7F0076B55C85668DF69375001
56
57
# Skip "Release" and "Packages" files hashes as they are unstable
58
# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with
59
# literal hashes, set them to SKIP with indexed assignments (pacman-contrib#119)
60
# https://gitlab.archlinux.org/pacman/pacman-contrib/-/issues/119
61
sha512sums[4]='SKIP'
62
sha512sums[6]='SKIP'
63
64
prepare() {
65
# Validate hashes from the PGP signed "Release" file
66
echo "$(grep non-free/binary-amd64/Packages ${pkgname}-${pkgver}-${pkgrel}-Release | tail -n 2 | head -n 1 | awk '{print $1}') ${pkgname}-${pkgver}-${pkgrel}-x86_64-Packages" \
67
> "${pkgname}-${pkgver}-x86_64-Packages.sha256"
68
sha256sum -c "${pkgname}-${pkgver}-x86_64-Packages.sha256"
69
70
echo "$(grep SHA512 ${pkgname}-${pkgver}-${pkgrel}-x86_64-Packages | head -n 1 | awk '{print $2}') ${pkgname}-${pkgver}-${_commit}-x86_64.deb" \
71
> "${pkgname}-${pkgver}-x86_64.deb.sha512"
72
sha512sum -c "${pkgname}-${pkgver}-x86_64.deb.sha512"
73
}
74
75
package() {
76
tar -xzf data.tar.gz --no-same-owner -C "${pkgdir}"
77
78
# Enable spotify to open URLs from the webapp
79
sed -i 's/^Exec=.*/Exec=spotify --uri=%u/' "${pkgdir}/usr/share/spotify/spotify.desktop"
80
81
install -Dm 644 "${pkgdir}/usr/share/spotify/spotify.desktop" "${pkgdir}/usr/share/applications/spotify.desktop"
82
install -Dm 644 "${pkgdir}/usr/share/spotify/icons/spotify-linux-512.png" "${pkgdir}/usr/share/pixmaps/spotify-client.png"
83
84
for size in 22 24 32 48 64 128 256 512; do
85
install -Dm 644 "${pkgdir}/usr/share/spotify/icons/spotify-linux-${size}.png" \
86
"${pkgdir}/usr/share/icons/hicolor/${size}x${size}/apps/spotify.png"
87
done
88
89
# Move spotify binary to its proper location
90
mkdir -p "${pkgdir}/opt/spotify"
91
mv "${pkgdir}/usr/share/spotify" "${pkgdir}/opt/"
92
93
# Copy launch script which allows the use of custom flags
94
install -Dm 755 spotify.sh "${pkgdir}/usr/bin/spotify"
95
96
# Copy protocol file for KDE
97
install -Dm 644 spotify.protocol "${pkgdir}/usr/share/kservices5/spotify.protocol"
98
99
# Install license
100
# https://www.spotify.com/legal/end-user-agreement
101
install -Dm 644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
102
103
# Fix permissions
104
chmod -R go-w "${pkgdir}"
105
}
106
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Medium | 2 |
| 2026-10-01 00:02:06 | Medium | 2 |
| 2026-09-30 00:20:07 | Medium | 2 |
| 2026-09-29 00:07:46 | Medium | 2 |
| 2026-09-28 00:28:32 | Medium | 2 |
| 2026-09-27 00:07:07 | Medium | 2 |
| 2026-09-26 00:12:15 | Medium | 2 |
| 2026-09-25 00:03:36 | Medium | 2 |
| 2026-09-24 00:24:14 | Medium | 2 |
| 2026-09-23 00:28:13 | Medium | 2 |
| 2026-09-22 00:15:14 | Medium | 2 |
| 2026-09-21 00:26:32 | Medium | 2 |
| 2026-09-20 00:25:31 | Medium | 2 |
| 2026-09-19 00:25:36 | Medium | 2 |
| 2026-09-18 00:17:11 | Medium | 2 |
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |