upm
The package installs a prebuilt binary from a non-whitelisted host (GitHub releases) with a fixed checksum, but the source is not compiled locally and could pose a supply-chain risk if the release asset were compromised.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-2507) reviewed it and judged it MEDIUM (confidence 95%): The package installs a prebuilt binary from a non-whitelisted host (GitHub releases) with a fixed checksum, but the source is not compiled locally and could pose a supply-chain risk if the release asset were compromised.
PKGBUILD
# Maintainer: Repl.it <contact+upm@repl.it>
pkgname=upm
pkgver=1.0
pkgrel=1
pkgdesc="Universal package manager: Python, Node.js, Ruby, Emacs Lisp."
arch=('any')
url=""
license=('MIT')
source=("https://github.com/replit/upm/releases/download/v${pkgver}/upm_${pkgver}_linux_amd64.tar.gz")
md5sums=('b5447e9387ac5d9c0d7c78106941cbef')
package() {
install -d "${pkgdir}/usr/bin"
cp "upm" "${pkgdir}/usr/bin/"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:13:36 | Medium | 2 |
| 2026-10-05 23:40:58 | Low | 1 |