tdarr

LOW
maintainer plasticbomb1986 3 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads prebuilt binaries from the project's own storage host (tdarr.io), which is not on a standard whitelist but is plausibly official; however, the lack of verifiable source code and use of non-public hosting introduces mild supply-chain risk, though the binaries are checksummed and the package installs only static files and systemd units without executing remote code.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt binaries from the project's own storage host (tdarr.io), which is not on a standard whitelist but is plausibly official; however, the lack of verifiable source code and use of non-public hosting introduces mild supply-chain risk, though the binaries are checksummed and the package installs only static files and systemd units without executing remote code.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:20 "https://storage.tdarr.io/versions/${pkgver}/linux_x64/Tdarr_Server.zip"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Attila Deak <plasticbomb1986@gmail.com>
2# Contributor: Mateusz Galazyn <carbolymer@gmail.com>
3
4pkgname='tdarr'
5pkgver=2.86.01
6pkgrel=1
7pkgdesc='Transcoding application manager for processing media libraries. Server + Node'
8arch=('x86_64')
9url='https://tdarr.io/'
10
11options=(!strip)
12
13depends=()
14
15makedepends=('unzip')
16
17optdepends=()
18
19source=(
20 "https://storage.tdarr.io/versions/${pkgver}/linux_x64/Tdarr_Server.zip"
21 "https://storage.tdarr.io/versions/${pkgver}/linux_x64/Tdarr_Node.zip"
22 'tdarr-node.service'
23 'tdarr-server.service'
24 'tdarr.sysusers'
25 'tdarr.tmpfiles'
26)
27
28noextract=(
29 'Tdarr_Server.zip'
30 'Tdarr_Node.zip'
31)
32sha256sums=(
33 'b29f60aaaabbc11fea5c5e81774ce4aed32595ce3f42a71b04e91569153aa12b'
34 'e40f871756a23cb8a08f769467e74831d2ac0c3a6234be07571be4b560ee9160'
35 '95e7c43861b6af12ff935063ede0287b6bb2d753299c5f26ca8e1841727dbdbb'
36 'cb11e62960ae73e21a13db5df0ad30d2ffff930108dc2d8e4321079a31c30d4e'
37 '3400d977769056ad626c065ada7fe74f3a2370b4faa090706110e7acedf70ffc'
38 '12cbabe6a417d17b30176c6f6916616fa86e0384ec8489e79551278808ec6376')
39
40prepare() {
41 mkdir -p "${srcdir}/server" "${srcdir}/node"
42 unzip Tdarr_Node.zip -d "${srcdir}/node"
43 unzip Tdarr_Server.zip -d "${srcdir}/server"
44}
45
46package() {
47 install -d -m 755 "${pkgdir}/var/lib/tdarr/server"
48 install -d -m 755 "${pkgdir}/var/lib/tdarr/node"
49 cp -dpr --no-preserve=ownership "${srcdir}/server/"* "${pkgdir}/var/lib/tdarr/server"
50 cp -dpr --no-preserve=ownership "${srcdir}/node/"* "${pkgdir}/var/lib/tdarr/node"
51
52 install -D -m 644 "${srcdir}/tdarr.sysusers" "${pkgdir}/usr/lib/sysusers.d/tdarr.conf"
53 install -D -m 644 "${srcdir}/tdarr-node.service" "${pkgdir}/usr/lib/systemd/system/tdarr-node.service"
54 install -D -m 644 "${srcdir}/tdarr-server.service" "${pkgdir}/usr/lib/systemd/system/tdarr-server.service"
55 install -D -m 644 "${srcdir}/tdarr.tmpfiles" "${pkgdir}/usr/lib/tmpfiles.d/tdarr.conf"
56}
57

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion