unichrom

maintainer kimond · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary archive (a zip containing an x86_64 Linux application) from the vendor's own domain (unichrom.com) and installs it directly into /opt. The checksum is SKIP, meaning there is no integrity verification. While unichrom.com appears to be the legitimate upstream vendor site (matching the package URL and description), the combination of: (1) a prebuilt binary blob installed directly to /opt, (2) no checksum verification (SKIP md5sums), and (3) a commercial closed-source application from a relatively obscure vendor constitutes a genuine supply-chain concern. If the host were compromised or the file silently replaced, arbitrary code would be executed on the user's system with no integrity check to catch it. The source host does match the official vendor URL, which reduces but does not eliminate the risk. This is a legitimate medium-severity concern: executed binary from a non-mainstream host with no checksum.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=("http://www.unichrom.com/chrom/install/uc-5.1.7.249-x86_64-linux-r11657M.zip")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary archive (a zip containing an x86_64 Linux application) from the vendor's own domain (unichrom.com) and installs it directly into /opt. The checksum is SKIP, meaning there is no integrity verification. While unichrom.com appears to be the legitimate upstream vendor site (matching the package URL and description), the combination of: (1) a prebuilt binary blob installed directly to /opt, (2) no checksum verification (SKIP md5sums), and (3) a commercial closed-source application from a relatively obscure vendor constitutes a genuine supply-chain concern. If the host were compromised or the file silently replaced, arbitrary code would be executed on the user's system with no integrity check to catch it. The source host does match the official vendor URL, which reduces but does not eliminate the risk. This is a legitimate medium-severity concern: executed binary from a non-mainstream host with no checksum.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Kim Desrosiers <kimdesro at gmail dot com>
2pkgname=unichrom
3pkgver=5.1.7.249
4pkgrel=1
5pkgdesc="fully automated Chromatographic Data System,
6dedicated to simplify hard, routine work of Chemist,
7dealing in a field of Gas and Liquid Chromatography."
8arch=("x86_64")
9url="http://www.unichrom.com/chrom/ucdle.php"
10license=('Commercial')
11source=("http://www.unichrom.com/chrom/install/uc-5.1.7.249-x86_64-linux-r11657M.zip")
12md5sums=("SKIP")
13
14
15package() {
16 cd "$srcdir"
17 install -d "$pkgdir"/{opt/$pkgname,usr/bin}
18 mv "$srcdir"/* "$pkgdir"/opt/$pkgname
19 install -D -m644 "$pkgdir"//opt/$pkgname/nas-uc.desktop "$pkgdir"/usr/share/applications/nas-uc.desktop
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion