spotify

MEDIUM
maintainer gromit 276 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

Downloads a prebuilt Debian package from a non-whitelisted but official Spotify domain, which is an unverifiable executable with supply-chain risk despite domain legitimacy.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:29 source=("${pkgname}-${pkgver}-${_commit}-x86_64.deb::http://repository.spotify.com/pool/non-free/s/spotify-client/spotify-client_${pkgver}.${_commit}_amd64.deb"
Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 90%): Downloads a prebuilt Debian package from a non-whitelisted but official Spotify domain, which is an unverifiable executable with supply-chain risk despite domain legitimacy.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Christian Heusel <christian@heusel.eu>
2# Maintainer: Robin Candau <antiz@archlinux.org>
3# Contributor: NicoHood <archlinux {cat} nicohood {dog} de>
4# Contributor: TobFromme < TobFromme {hat} pm {dont} me >
5# Contributor: Ashley Whetter <(firstname) @ awhetter.co.uk>
6# Contributor: Eothred <yngve.levinsen@gmail.com>
7
8pkgname=spotify
9pkgver='1.2.96.518'
10epoch=1
11_commit=g366879e1
12pkgrel=2
13pkgdesc='A proprietary music streaming service'
14arch=('x86_64')
15license=('custom')
16url='https://www.spotify.com'
17depends=('alsa-lib>=1.0.14' 'gtk3' 'libxss' 'desktop-file-utils' 'openssl' 'nss' 'at-spi2-atk' 'libcurl-gnutls' 'libsm' 'libayatana-appindicator' 'libayatana-indicator')
18optdepends=('ffmpeg4.4: Adds support for playback of local files'
19 'zenity: Adds support for importing local files'
20 'libnotify: Desktop notifications')
21options=('!strip')
22
23# NOTE: We switched from stable to testing on 18th march, as the spotify
24# stable repository is always outdated. Testing seems to be in sync with snap:
25# https://snapcraft.io/spotify
26# http://repository.spotify.com/dists/testing/Release
27# http://repository.spotify.com/dists/testing/non-free/binary-amd64/Packages
28# http://repository.spotify.com/dists/testing/Release.gpg
29source=("${pkgname}-${pkgver}-${_commit}-x86_64.deb::http://repository.spotify.com/pool/non-free/s/spotify-client/spotify-client_${pkgver}.${_commit}_amd64.deb"
30 "spotify.sh"
31 "spotify.protocol"
32 "LICENSE"
33 # GPG signature check
34 "${pkgname}-${pkgver}-${pkgrel}-Release::http://repository.spotify.com/dists/testing/Release"
35 "${pkgname}-${pkgver}-${pkgrel}-Release.sig::http://repository.spotify.com/dists/testing/Release.gpg"
36 "${pkgname}-${pkgver}-${pkgrel}-x86_64-Packages::http://repository.spotify.com/dists/testing/non-free/binary-amd64/Packages")
37sha512sums=('98d25bd748258ca8b8357313cd35c7188bb0b26ed2d4390b0208473aa9fa3491a095559762f8ba06ec0828d73e05ee8fb488f0f357340191da4c65dd1f93c519'
38 'da48b628a4ea925dd8521133ebf364b261b11aed252d264dde6605d915cdb631919ffe672c58534bcdb60869e5d87a49a60a8198780b99517123f0031e83fdb1'
39 '999abe46766a4101e27477f5c9f69394a4bb5c097e2e048ec2c6cb93dfa1743eb436bde3768af6ba1b90eaac78ea8589d82e621f9cbe7d9ab3f41acee6e8ca20'
40 '2e16f7c7b09e9ecefaa11ab38eb7a792c62ae6f33d95ab1ff46d68995316324d8c5287b0d9ce142d1cf15158e61f594e930260abb8155467af8bc25779960615'
41 '18f27971697835df865d63465d86d1250b20b9d1c12bbf7df1eafeef5c66bf0b3134c25b08269f72d4b7a4287151336ee3fd0f70bc46da25f13e8c91c004f710'
42 'SKIP'
43 '1fbb6f1f104b998265faafeb62cb3aff6d7048b2e689292049fbbe867ea4071af3b73fc5a023bff8d4c1e579e5d904c78179e3650ae4740602583db8e13bde8a')
44
45# Import key with:
46# curl -sS https://download.spotify.com/debian/pubkey_5384CE82BA52C83A.gpg | gpg --import -
47validpgpkeys=('E1096BCBFF6D418796DE78515384CE82BA52C83A') # Spotify Public Repository Signing Key <tux@spotify.com>
48# Old Keys:
49# 63CBEEC9006602088F9B19326224F9941A8AA6D1
50# E27409F51D1B66337F2D2F417A3A762FAFD4A51F
51# F9A211976ED662F00E59361E5E3C45D7B312C643
52# 8FD3D9A8D3800305A9FFF259D1742AD60D811D58
53# 931FF8E79F0876134EDDBDCCA87FF9DF48BF1C90
54# 2EBF997C15BDA244B6EBF5D84773BD5E130D1D45
55# B420FD3777CCE3A7F0076B55C85668DF69375001
56
57# Skip "Release" and "Packages" files hashes as they are unstable
58# Since "updpkgsums"/"pkgctl version upgrade" overwrite the checksum array with
59# literal hashes, set them to SKIP with indexed assignments (pacman-contrib#119)
60# https://gitlab.archlinux.org/pacman/pacman-contrib/-/issues/119
61sha512sums[4]='SKIP'
62sha512sums[6]='SKIP'
63
64prepare() {
65 # Validate hashes from the PGP signed "Release" file
66 echo "$(grep non-free/binary-amd64/Packages ${pkgname}-${pkgver}-${pkgrel}-Release | tail -n 2 | head -n 1 | awk '{print $1}') ${pkgname}-${pkgver}-${pkgrel}-x86_64-Packages" \
67 > "${pkgname}-${pkgver}-x86_64-Packages.sha256"
68 sha256sum -c "${pkgname}-${pkgver}-x86_64-Packages.sha256"
69
70 echo "$(grep SHA512 ${pkgname}-${pkgver}-${pkgrel}-x86_64-Packages | head -n 1 | awk '{print $2}') ${pkgname}-${pkgver}-${_commit}-x86_64.deb" \
71 > "${pkgname}-${pkgver}-x86_64.deb.sha512"
72 sha512sum -c "${pkgname}-${pkgver}-x86_64.deb.sha512"
73}
74
75package() {
76 tar -xzf data.tar.gz --no-same-owner -C "${pkgdir}"
77
78 # Enable spotify to open URLs from the webapp
79 sed -i 's/^Exec=.*/Exec=spotify --uri=%u/' "${pkgdir}/usr/share/spotify/spotify.desktop"
80
81 install -Dm 644 "${pkgdir}/usr/share/spotify/spotify.desktop" "${pkgdir}/usr/share/applications/spotify.desktop"
82 install -Dm 644 "${pkgdir}/usr/share/spotify/icons/spotify-linux-512.png" "${pkgdir}/usr/share/pixmaps/spotify-client.png"
83
84 for size in 22 24 32 48 64 128 256 512; do
85 install -Dm 644 "${pkgdir}/usr/share/spotify/icons/spotify-linux-${size}.png" \
86 "${pkgdir}/usr/share/icons/hicolor/${size}x${size}/apps/spotify.png"
87 done
88
89 # Move spotify binary to its proper location
90 mkdir -p "${pkgdir}/opt/spotify"
91 mv "${pkgdir}/usr/share/spotify" "${pkgdir}/opt/"
92
93 # Copy launch script which allows the use of custom flags
94 install -Dm 755 spotify.sh "${pkgdir}/usr/bin/spotify"
95
96 # Copy protocol file for KDE
97 install -Dm 644 spotify.protocol "${pkgdir}/usr/share/kservices5/spotify.protocol"
98
99 # Install license
100 # https://www.spotify.com/legal/end-user-agreement
101 install -Dm 644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
102
103 # Fix permissions
104 chmod -R go-w "${pkgdir}"
105}
106

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Medium 2
2026-10-01 00:02:06 Medium 2
2026-09-30 00:20:07 Medium 2
2026-09-29 00:07:46 Medium 2
2026-09-28 00:28:32 Medium 2
2026-09-27 00:07:07 Medium 2
2026-09-26 00:12:15 Medium 2
2026-09-25 00:03:36 Medium 2
2026-09-24 00:24:14 Medium 2
2026-09-23 00:28:13 Medium 2
2026-09-22 00:15:14 Medium 2
2026-09-21 00:26:32 Medium 2
2026-09-20 00:25:31 Medium 2
2026-09-19 00:25:36 Medium 2
2026-09-18 00:17:11 Medium 2
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion