sqrxz
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("https://www.retroguru.com/$pkgname/$pkgname-v0996a-ubuntu.tar.gz"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary tarball (containing sqrxz_ubuntu32 and sqrxz_ubuntu64 executables) from retroguru.com, which is a third-party retro gaming distribution site rather than the official sqrxz.de project host. The binaries are installed and executed directly. While retroguru.com appears to be a legitimate retro game distribution platform that has hosted Sqrxz for years (the game's own site links to it), it is still a third-party host for executed binaries rather than the upstream project's own infrastructure. The sha256sums provide integrity checking against tampering in transit, but do not protect against the host itself serving malicious content or being compromised. This is a genuine medium-severity supply-chain concern: prebuilt closed-source binaries from a non-primary host with no source build option. The cheaper model's assessment is correct here — this is a real (if modest) supply-chain risk, not a false positive.
PKGBUILD
1 offending line(s) highlighted# Maintainer: kleintux <reg-archlinux AT klein DOT tuxli DOT ch>
# Contributor: carstene1ns <arch carsten-teibes de> - http://git.io/ctPKG
pkgname=sqrxz
pkgver=0.996a
pkgrel=4
pkgdesc="A fast paced jump'n'run which will please the hardcore gamer amongst you"
arch=('i686' 'x86_64')
url="https://www.sqrxz.de/sqrxz/"
license=('custom: Freeware')
depends=('sdl_mixer' 'zlib')
optdepends=('libmodplug: better music decoder')
install=$pkgname.install
source=("https://www.retroguru.com/$pkgname/$pkgname-v0996a-ubuntu.tar.gz"
"$pkgname.png"
"$pkgname.sh"
"$pkgname.desktop")
sha256sums=('1986ba52187e2e1c91114631209d24bcf7438174b81c4c69469d8a181e6fe31c'
'1113cd762c2daedf7eb81872117b40b7ffd0be297db2e1d76284db531ce5025a'
'0468a24a04256865381f5dd0c92dfed4ed6f594270760f32678ebe2cb9bc1b5c'
'e50418c74fc18283197a0f3ef4fdadd697f0c517de35d09bffcc8d0b5eb4ac49')
options=(!strip)
package() {
# create folders
install -d "$pkgdir"/usr/{lib/$pkgname,share/{{doc,licenses}/$pkgname,$pkgname/data}}
# install architecture dependent executable
case $CARCH in
i686)
install -m755 ${pkgname}_ubuntu32 "$pkgdir"/usr/lib/$pkgname/$pkgname;;
x86_64)
install -m755 ${pkgname}_ubuntu64 "$pkgdir"/usr/lib/$pkgname/$pkgname;;
esac
# install launcher, data, text, icon, desktop and license files
install -Dm755 $pkgname.sh "$pkgdir"/usr/bin/$pkgname
install -m644 data/*.zda "$pkgdir"/usr/share/$pkgname/data
install -m644 *.txt "$pkgdir"/usr/share/doc/$pkgname
install -Dm644 $pkgname.png "$pkgdir"/usr/share/pixmaps/$pkgname.png
install -Dm644 $pkgname.desktop "$pkgdir"/usr/share/applications/$pkgname.desktop
tail -n +16 readme.txt | head -n 17 > "$pkgdir"/usr/share/licenses/$pkgname/FREEWARE
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |