tateditor-bin

maintainer roistaff · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads a prebuilt binary tarball from Google Drive (an unofficial, personal/unverifiable host) with sha256sums='SKIP', meaning no integrity verification is performed. The binary is then executed directly from the user's home directory. Google Drive links can be replaced or modified by the uploader at any time without notice, and there is no way to verify the binary's authenticity or integrity. This is a textbook supply-chain risk: an executed binary from a non-official host with no checksum. The cheaper model's MEDIUM rating is correct.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=("tateditor.tar.gz::https://drive.google.com/uc?export=download&id=1nIb3ocWZp7y5NwQt4K_M1F8G_r1YjMdg")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 85%): This PKGBUILD downloads a prebuilt binary tarball from Google Drive (an unofficial, personal/unverifiable host) with sha256sums='SKIP', meaning no integrity verification is performed. The binary is then executed directly from the user's home directory. Google Drive links can be replaced or modified by the uploader at any time without notice, and there is no way to verify the binary's authenticity or integrity. This is a textbook supply-chain risk: an executed binary from a non-official host with no checksum. The cheaper model's MEDIUM rating is correct.

PKGBUILD

1 offending line(s) highlighted
1pkgname=tateditor-bin
2pkgver=1.0
3pkgrel=1
4pkgdesc="TATEditor (GTK3 build, binary release)"
5arch=('x86_64')
6url="https://drive.google.com/file/d/1nIb3ocWZp7y5NwQt4K_M1F8G_r1YjMdg/view"
7license=('custom')
8depends=('gtk3')
9source=("tateditor.tar.gz::https://drive.google.com/uc?export=download&id=1nIb3ocWZp7y5NwQt4K_M1F8G_r1YjMdg")
10sha256sums=('SKIP')
11
12package() {
13 # system template files
14 install -d "${pkgdir}/usr/share/tateditor"
15 cp -r "${srcdir}/tateditor-gtk3-x86_64/"* "${pkgdir}/usr/share/tateditor/"
16
17 # wrapper
18 install -d "${pkgdir}/usr/bin"
19 cat > "${pkgdir}/usr/bin/tateditor" <<'EOF'
20#!/bin/bash
21userdir="$HOME/.local/share/tateditor"
22if [ ! -d "$userdir" ]; then
23 mkdir -p "$userdir"
24 cp -r /usr/share/tateditor/* "$userdir/"
25fi
26cd "$userdir"
27exec ./tateditor "$@"
28EOF
29 chmod +x "${pkgdir}/usr/bin/tateditor"
30
31 # desktop entry
32 install -d "${pkgdir}/usr/share/applications"
33 cat > "${pkgdir}/usr/share/applications/tateditor.desktop" <<EOF
34[Desktop Entry]
35Name=TATEditor
36Exec=tateditor
37Icon=accessories-text-editor
38Type=Application
39Categories=Utility;TextEditor;
40EOF
41}
42
43

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion