upm

MEDIUM
maintainer orphaned 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package installs a prebuilt binary from a non-whitelisted host (GitHub releases) with a fixed checksum, but the source is not compiled locally and could pose a supply-chain risk if the release asset were compromised.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 95%): The package installs a prebuilt binary from a non-whitelisted host (GitHub releases) with a fixed checksum, but the source is not compiled locally and could pose a supply-chain risk if the release asset were compromised.

PKGBUILD

1# Maintainer: Repl.it <contact+upm@repl.it>
2pkgname=upm
3pkgver=1.0
4pkgrel=1
5pkgdesc="Universal package manager: Python, Node.js, Ruby, Emacs Lisp."
6arch=('any')
7url=""
8license=('MIT')
9source=("https://github.com/replit/upm/releases/download/v${pkgver}/upm_${pkgver}_linux_amd64.tar.gz")
10md5sums=('b5447e9387ac5d9c0d7c78106941cbef')
11
12package() {
13 install -d "${pkgdir}/usr/bin"
14 cp "upm" "${pkgdir}/usr/bin/"
15}
16

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Medium 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion