xdao

maintainer Malingshu · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary artifact from nightly.link, which is a third-party proxy service for GitHub Actions artifacts. While nightly.link does serve genuine GitHub Actions build artifacts, it is not the project's official release infrastructure (no tagged release, no official download URL). The artifact is a compiled executable that gets installed directly to /usr/bin. Additionally, sha256sums is set to 'SKIP', meaning there is no integrity verification whatsoever — the binary could be substituted at any time without detection. This combination (prebuilt binary from a non-official proxy host + no checksum verification) constitutes a real supply-chain risk: the artifact could be swapped on nightly.link or via a GitHub Actions workflow compromise, and the package would install whatever binary is served without any verification. This is a genuine medium-severity concern.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:18 source=("https://nightly.link/TransparentLC/xdcmd/workflows/build/master/xdcmd-ubuntu.zip")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt binary artifact from nightly.link, which is a third-party proxy service for GitHub Actions artifacts. While nightly.link does serve genuine GitHub Actions build artifacts, it is not the project's official release infrastructure (no tagged release, no official download URL). The artifact is a compiled executable that gets installed directly to /usr/bin. Additionally, sha256sums is set to 'SKIP', meaning there is no integrity verification whatsoever — the binary could be substituted at any time without detection. This combination (prebuilt binary from a non-official proxy host + no checksum verification) constitutes a real supply-chain risk: the artifact could be swapped on nightly.link or via a GitHub Actions workflow compromise, and the package would install whatever binary is served without any verification. This is a genuine medium-severity concern.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: TransparentLC <akarin.dev>
2# Packager: Malingshu <myy0222@gmail.com>
3
4pkgname=xdao
5pkgrel=1
6pkgver=1.2.0.230425
7pkgdesc="An nmbXD TUI cli written in Python."
8arch=('any')
9url="https://github.com/TransparentLC/xdcmd"
10license=('AGPL-3.0')
11sha256sums=('SKIP')
12depends=(
13 'imagemagick'
14 'glib2'
15 )
16makedepends=()
17install=${pkgname}.install
18source=("https://nightly.link/TransparentLC/xdcmd/workflows/build/master/xdcmd-ubuntu.zip")
19
20
21package() {
22 cd "${pkgdir}"
23 mkdir -p usr/bin
24 mkdir -p usr/share/xdao
25 tar -xvJf ${srcdir}/xdcmd-ubuntu.tar.xz -C usr/share/xdao
26 ln -s /usr/share/xdao/xdcmd-ubuntu/xdcmd usr/bin/xdao
27}
28

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion