tonelib-tube-warmth-bin

maintainer Versua7 · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads a prebuilt binary .deb from tonelib.net (the official vendor website for ToneLib products) and installs it directly. The URL points to the vendor's own domain, which is consistent with other ToneLib packages in the AUR (tonelib-gfx, tonelib-zoom, etc.) that follow the same pattern. However, the concern is real: a prebuilt closed-source binary is extracted and installed without any code review possible, and the sha256sum is hardcoded but cannot be independently verified against a signed release manifest (ToneLib does not publish GPG-signed checksums). The binary is executed at runtime by users, so if the vendor's download were compromised or the binary were swapped, users would run malicious code. This is a classic supply-chain medium: not clearly malicious, the vendor domain appears legitimate, but it is a closed-source binary from a non-auditable host with no cryptographic signing beyond the PKGBUILD's own checksum. The PKGBUILD itself is structurally correct and functional.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("${pkgname}-${pkgver}.deb::https://tonelib.net/download/ToneLib-TubeWarmth-amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads a prebuilt binary .deb from tonelib.net (the official vendor website for ToneLib products) and installs it directly. The URL points to the vendor's own domain, which is consistent with other ToneLib packages in the AUR (tonelib-gfx, tonelib-zoom, etc.) that follow the same pattern. However, the concern is real: a prebuilt closed-source binary is extracted and installed without any code review possible, and the sha256sum is hardcoded but cannot be independently verified against a signed release manifest (ToneLib does not publish GPG-signed checksums). The binary is executed at runtime by users, so if the vendor's download were compromised or the binary were swapped, users would run malicious code. This is a classic supply-chain medium: not clearly malicious, the vendor domain appears legitimate, but it is a closed-source binary from a non-auditable host with no cryptographic signing beyond the PKGBUILD's own checksum. The PKGBUILD itself is structurally correct and functional.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Versua7 <versua7@gmail.com>
2
3pkgname='tonelib-tube-warmth-bin'
4pkgver=1.5.0
5pkgrel=1
6pkgdesc="ToneLib Tube Warmth – The vibrancy and warmth of the tube along with the digital precision and clarity"
7arch=('x86_64')
8license=('custom')
9url="https://tonelib.net/tl-tubewarmth.html"
10depends=('gtk3' 'glib2' 'desktop-file-utils' 'alsa-lib' 'harfbuzz' 'fribidi' 'pango' 'freetype2')
11optdepends=('jack: JACK output')
12source=("${pkgname}-${pkgver}.deb::https://tonelib.net/download/ToneLib-TubeWarmth-amd64.deb")
13sha256sums=('5c19f26282c2204d21bd0b7dd4adc31eb8e6e12923ce0c05de0e05e4604a64b8')
14
15package () {
16 tar xf data.tar.xz -C "${pkgdir}"
17 install -D -m644 "${pkgdir}/usr/share/doc/tonelib-tubewarmth/copyright" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
18}
19
20post_install() {
21 gtk-update-icon-cache -q -t -f usr/share/icons/hicolor
22 update-desktop-database -q
23}
24
25post_remove() {
26 gtk-update-icon-cache -q -t -f usr/share/icons/hicolor
27 update-desktop-database -q
28}
29

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion