synology-drive
The package downloads a prebuilt .deb from a Synology-hosted domain, which is plausible but not on a standard whitelist; installing a prebuilt binary from an unverifiable source with a fixed checksum carries a moderate supply-chain risk if the host were compromised.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
source_x86_64=("https://global.synologydownload.com/download/Utility/SynologyDriveClient/${_pkgver}-${_pkgrel}/Ubuntu/Installer/synology-drive-client-${_pkgrel}.${arch}.deb")
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt .deb from a Synology-hosted domain, which is plausible but not on a standard whitelist; installing a prebuilt binary from an unverifiable source with a fixed checksum carries a moderate supply-chain risk if the host were compromised.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Matt Warner <mattwarner001@gmail.com>
# Contributor: Helmut Stult <hst[at]e-mail[dot]de>
# Contributor: Felipe Martin <me@fmartingr.com>
pkgname=synology-drive
pkgver=4.2.0_20058
_pkgver=4.2.0
_pkgrel=20058
pkgrel=1
pkgdesc="Desktop utility of the DSM add-on package, Synology Drive Server"
arch=('x86_64')
url="https://www.synology.com/en-global/releaseNote/SynologyDriveClient"
license=('custom:Synology Linux License Grant')
depends=('glib2' 'glibc' 'qt5-base' 'qt5-wayland' 'curl' 'libarchive' 'libxkbcommon' 'libice' 'libsm' 'hicolor-icon-theme')
makedepends=('qt5-tools')
optdepends=('nautilus: For nautilus integration')
conflicts=('synology-drive' 'synology-drive-client' 'cloudstation-beta' 'cloudstation-3.0' 'cloudstation-drive')
source_x86_64=("https://global.synologydownload.com/download/Utility/SynologyDriveClient/${_pkgver}-${_pkgrel}/Ubuntu/Installer/synology-drive-client-${_pkgrel}.${arch}.deb")
sha256sums_x86_64=('430031fdf5a12e655ce5cfc6b964d9b5cbdddebccdbf3fa6b5660546cb91f99d')
package() {
cd "${srcdir}"
tar -xJf data.tar.xz -C "${pkgdir}"
install -Dm 644 "${pkgdir}"/opt/Synology/SynologyDrive/LICENSE.txt "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Medium | 2 |
| 2026-10-01 00:02:06 | Medium | 2 |
| 2026-09-30 00:20:07 | Medium | 2 |
| 2026-09-29 00:07:46 | Medium | 2 |
| 2026-09-28 00:28:32 | Medium | 2 |
| 2026-09-27 00:07:07 | Medium | 2 |
| 2026-09-26 00:12:15 | Medium | 2 |
| 2026-09-25 00:03:36 | Medium | 2 |
| 2026-09-24 00:24:14 | Medium | 2 |
| 2026-09-23 00:28:13 | Medium | 2 |
| 2026-09-22 00:15:14 | Medium | 2 |
| 2026-09-21 00:26:32 | Medium | 2 |
| 2026-09-20 00:25:31 | Medium | 2 |
| 2026-09-19 00:25:36 | Medium | 2 |
| 2026-09-18 00:17:11 | Medium | 2 |
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 3 |