xj-gomoku

maintainer XIAOJIN · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from lideying.cn, which is not the upstream project host (gitee.com/xiaojinpro/xj-gomoku). This is a personal/third-party Chinese domain hosting an executable artifact (a GTK/WebKit2 gomoku game binary). The package installs this binary directly without building from source. While a sha256sum is provided, the host is not the canonical upstream, meaning if lideying.cn is compromised or the file is swapped, users would execute arbitrary code. The WebKit2GTK dependency also suggests this is an Electron/web-based app with significant attack surface. This is a genuine supply-chain concern: an executed binary from an unofficial, non-project-owned host.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("https://www.lideying.cn/resource/xj-gomoku/"$pkgname"_"$pkgver"_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt binary .deb from lideying.cn, which is not the upstream project host (gitee.com/xiaojinpro/xj-gomoku). This is a personal/third-party Chinese domain hosting an executable artifact (a GTK/WebKit2 gomoku game binary). The package installs this binary directly without building from source. While a sha256sum is provided, the host is not the canonical upstream, meaning if lideying.cn is compromised or the file is swapped, users would execute arbitrary code. The WebKit2GTK dependency also suggests this is an Electron/web-based app with significant attack surface. This is a genuine supply-chain concern: an executed binary from an unofficial, non-project-owned host.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer:
2# Contributor:
3pkgname=xj-gomoku
4pkgver=1.0.0
5pkgrel=1
6pkgdesc="gomoku"
7arch=('any')
8url="https://gitee.com/xiaojinpro/xj-gomoku.git#branch=online"
9license=('mit')
10depends=('cairo' 'desktop-file-utils' 'gdk-pixbuf2' 'glib2' 'gtk3' 'hicolor-icon-theme' 'libsoup' 'pango' 'webkit2gtk-4.1')
11options=('!strip' '!emptydirs')
12install=${pkgname}.install
13source=("https://www.lideying.cn/resource/xj-gomoku/"$pkgname"_"$pkgver"_amd64.deb")
14sha256sums=('7f0f14843f0bd517fe1cc438a28c69611b2c4848ac5a33511b6df9b828dfa668')
15package() {
16
17 # Extract package data
18 tar -xz -f data.tar.gz -C "${pkgdir}"
19
20}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion