virtualhub
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:23
source=("https://www.yoctopuce.com/FR/downloads/VirtualHub.linux.${pkgver}.zip"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt x86_64 binary (VirtualHub) from yoctopuce.com, which is the official vendor website for Yoctopuce USB devices. The host is legitimate and vendor-controlled, not a personal or unofficial mirror. However, the checksum is set to SKIP, meaning there is no integrity verification of the downloaded binary. A prebuilt binary installed to /usr/bin with 755 permissions and no checksum validation represents a real supply-chain concern: if the download were intercepted (MITM, CDN compromise, or the vendor's server were compromised), an arbitrary binary would be executed with no detection. The source host being the official vendor site reduces but does not eliminate the risk — SKIP on an executed binary is always a concern. This is a genuine medium: not clearly malicious, but a real code-execution supply-chain risk due to the missing integrity check on a prebuilt binary.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Gerard Salvatella <mail@gerardsalvatella.com>
pkgname=virtualhub
pkgver=56436
pkgrel=1
epoch=
pkgdesc="Toolbox for Yoctopuce USB devices"
arch=('x86_64')
url="https://www.yoctopuce.com"
license=('GPL')
groups=()
depends=()
makedepends=()
checkdepends=()
optdepends=("yoctolib-cmdlines: cli binaries")
provides=()
conflicts=()
replaces=()
backup=()
options=()
install=virtualhub.install
changelog=
source=("https://www.yoctopuce.com/FR/downloads/VirtualHub.linux.${pkgver}.zip"
)
noextract=()
sha256sums=("SKIP"
)
validpgpkeys=()
package() {
install -d "${pkgdir}/usr/bin/" "${pkgdir}/usr/lib/systemd/system/" "${pkgdir}/etc/udev/rules.d/"
install -Dm755 "64bits/VirtualHub" "${pkgdir}/usr/bin"
install -Dm644 "startup_script/y${pkgname}.service" "${pkgdir}/usr/lib/systemd/system/"
install -Dm644 udev_conf/* "${pkgdir}/etc/udev/rules.d/"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |