waves-exchange

maintainer lcdss · 3 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt .deb binary directly from waves.exchange/files/Waves.Exchange.deb — a non-versioned, mutable URL (no version in the path) that always points to whatever file the server currently serves. While waves.exchange is the official project domain, the URL is not pinned to a specific release version, meaning the file could be silently replaced at any time. The md5sums check provides weak integrity (MD5 is cryptographically broken and the checksum would need to be updated manually if the file changes). The package extracts and installs a prebuilt Electron/native binary into /opt and creates a symlink in /usr/bin — this is executed code from a non-reproducible, non-versioned binary blob. This is a genuine medium-severity supply-chain concern: not clearly malicious, but the combination of a mutable URL, weak integrity check, and directly executed binary warrants the rating. It is not high because the domain is the official project domain and there is no evidence of active compromise or obfuscation.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=("https://waves.exchange/files/Waves.Exchange.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt .deb binary directly from waves.exchange/files/Waves.Exchange.deb — a non-versioned, mutable URL (no version in the path) that always points to whatever file the server currently serves. While waves.exchange is the official project domain, the URL is not pinned to a specific release version, meaning the file could be silently replaced at any time. The md5sums check provides weak integrity (MD5 is cryptographically broken and the checksum would need to be updated manually if the file changes). The package extracts and installs a prebuilt Electron/native binary into /opt and creates a symlink in /usr/bin — this is executed code from a non-reproducible, non-versioned binary blob. This is a genuine medium-severity supply-chain concern: not clearly malicious, but the combination of a mutable URL, weak integrity check, and directly executed binary warrants the rating. It is not high because the domain is the official project domain and there is no evidence of active compromise or obfuscation.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer Lucas Silva <lcdss[at]live[dot]com>
2
3pkgname=waves-exchange
4pkgver=1.0.0
5pkgrel=2
6pkgdesc="Waves.Exchange is an exchange that combines the advantages of centralized and decentralized digital trading approaches"
7url="https://waves.exchange"
8license=('MIT')
9source=("https://waves.exchange/files/Waves.Exchange.deb")
10arch=('x86_64')
11md5sums=('1867cef5e7098d6bdcd98944f38938ff')
12depends=()
13
14package() {
15 bsdtar -O -xf Waves.Exchange.deb data.tar.xz | bsdtar -C "${pkgdir}" -xJf -
16 find "${pkgdir}" -type d -exec chmod 755 {} +
17
18 mkdir -p "$pkgdir/usr/bin"
19 ln -s "/opt/Waves.Exchange/waves-exchange" "${pkgdir}/usr/bin/waves-exchange"
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion